19.07.2013 Views

Volume 14 Number 3 (July to September 2003) - University of the ...

Volume 14 Number 3 (July to September 2003) - University of the ...

Volume 14 Number 3 (July to September 2003) - University of the ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>14</strong>26<br />

National Administrative Register <strong>Volume</strong> <strong>14</strong>/3<br />

SECTION 8. Liability for unauthorized use <strong>of</strong> secure electronic signatures - Where<br />

<strong>the</strong> use <strong>of</strong> a secure electronic signature was unauthorized and <strong>the</strong> purported signer did not<br />

exercise reasonable care <strong>to</strong> avoid <strong>the</strong> unauthorized use <strong>of</strong> <strong>the</strong> signature or <strong>to</strong> prevent <strong>the</strong><br />

addressee from relying on such a signature, <strong>the</strong> signature shall never<strong>the</strong>less be regarded as<br />

that <strong>of</strong> <strong>the</strong> purported signer, unless <strong>the</strong> relying party knew or should have known that <strong>the</strong><br />

signature was not that <strong>of</strong> <strong>the</strong> purported signer.<br />

SECTION 9. Responsibilities <strong>of</strong> an information certifier - An information certifier<br />

shall:<br />

a. act in accordance with <strong>the</strong> representations it makes with respect <strong>to</strong> its practices;<br />

b. excercise due diligence <strong>to</strong> ensure <strong>the</strong> accuracy and completeness <strong>of</strong> all material representations<br />

it makes that are relevant <strong>to</strong> <strong>the</strong> life-cycle <strong>of</strong> its certificates or which are included<br />

in its certificates;<br />

c. provide reasonably accessible means which enable a relying party <strong>to</strong> ascertain:<br />

i. <strong>the</strong> identity <strong>of</strong> <strong>the</strong> information certifier;<br />

ii. that <strong>the</strong> person who is identified in <strong>the</strong> certificate holds, at <strong>the</strong> relevant time, <strong>the</strong><br />

signature device referred <strong>to</strong> in <strong>the</strong> certificate;<br />

iii. <strong>the</strong> method used <strong>to</strong> identify <strong>the</strong> signer, provided however <strong>the</strong> information certifier<br />

shall not be required <strong>to</strong> reveal any <strong>of</strong> its trade or industrial secrets;<br />

iv. any limitations on <strong>the</strong> purposes or value for which <strong>the</strong> signature device may be<br />

used; and<br />

v. whe<strong>the</strong>r <strong>the</strong> signature device is valid and has not been compromised;<br />

d. Provide reasonably accessible means for signer <strong>to</strong> give notice that a signature device has<br />

been compromised and ensure <strong>the</strong> operation <strong>of</strong> a timely and secure revocation service; and<br />

e. Utilize trustworthy systems, and procedures in performing its services.<br />

f. Engage trustworthly personnel who possess <strong>the</strong> expert knowledge, experience and qualifications<br />

necessary for its services, in particular, but not limited <strong>to</strong>, expertise in electronic<br />

signature technology and familiarity with proper security procedures;<br />

g. Maintain sufficient financial resources <strong>to</strong> operate as an information certifier and <strong>to</strong> bear<br />

<strong>the</strong> risk <strong>of</strong> potential liability for damages;<br />

h. Record, whe<strong>the</strong>r electronically or not, for an appropriate period <strong>of</strong> time all relevant information<br />

concerning issued certificates for, but not limited <strong>to</strong>, <strong>the</strong> purpose <strong>of</strong> providing evidence<br />

<strong>of</strong> certification in legal proceedings;<br />

i. For purposes <strong>of</strong> issuing and maintaining a certificate, collect and utilize personal data only<br />

ins<strong>of</strong>ar as it is necessary for <strong>the</strong> purpose <strong>of</strong> issuing and maintaining <strong>the</strong> certificate. Such

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!