|
The CA facility must be protected by at least three tiers of physical security, with access to the lower tier required before gaining access to the higher tier.
- Tier 1 - Entry to the Site in the vicinity is after entry to a log register for visitors and proper physical verification by the security guard at the entrance.
- Tier 2 - The entry to the working area is through a proximity access control system imposing the second tier of security. Physical access to tier three is automatically logged.
- Tier 3 - The main room where cryptographic operation takes place should be constructed as per the details given in the para 2. Activities related to the lifecycle of the certification process such as authentication, verification, and issuance takes place in this area. This security barrier enforces individual access control through the use of two factor authentication including biometrics. Unescorted personnel, including untrusted employees or visitors, are not allowed into a tier-three secured area. Physical access to tier three is automatically logged
In addition to the aforesaid tiers, additional tiers can be added.
Construction of Cryptographic Operation Site
Broad Specifications of Systems to be installed
References
|