Presentation is loading. Please wait.

Presentation is loading. Please wait.

©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 PKI Audits and Assessments: An insider’s.

Similar presentations


Presentation on theme: "©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 PKI Audits and Assessments: An insider’s."— Presentation transcript:

1 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 PKI Audits and Assessments: An insider’s view Nathan Faut, Senior Associate KPMG

2 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 Agenda Background PKI “Audit” Activities PKI and other “Audit” Activities Short-term look into what’s ahead Q&A

3 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 Background CISA, December 2005 Completed Web Trust engagements for DEA, USPS Previously helped establish HEPKI PA Previously worked with Cybertrust, a PKI vendor

4 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 PKI “Audit” Activities Audit vs. attestation ABA PKI Assessment Guidelines CA Control Objectives CA Audit criteria –AICPA/CICA Web Trust for CA –FBCA Compliance Assessments “The trust is in the auditor’s opinion” – Judy Spencer

5 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 Other “Audit” Criteria and Controls Certification & Accreditation (C&A) per OMB A-130, NIST 800-37, 800-53, et.al. Federal Information Security Management Act (FISMA) Financial Audits

6 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 CA “Audit” Expectations Have all CA documents in final form and ready (tip: do a pre-audit CP-to-CPS map) Plan to reproduce 6 to 12 months of data including physical access logs, server logs, incident logs and reports, etc. Decide what documents or parts of documents to make public Expect to educate and be educated

7 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 What’s Next? HSPD 12 credentials Bridge-to-Bridge Cross Certifications, e.g. FBCA-Certipath Federation Compliance Registration Compliance Commoditization

8 ©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 Q&A Thank You Nathan Faut nfaut@kpmg.com 202-533-4471


Download ppt "©2005 KPMG LLP, the U.S. member firm of KPMG International, a Swiss cooperative. All rights reserved. July 27, 2005 PKI Audits and Assessments: An insider’s."

Similar presentations


Ads by Google