Skip to content

Certificate Authority

What is Certificate Authority?

A trusted entity that issues digital certificates used to verify the identity of individuals, organisations, or devices. Certificate Authorities form the basis of the Public Key Infrastructure (PKI) trust model.

Information Security

What the standards actually require on certificate authority

Requirements naming certificate authority across 4 standards, quoted from the control text.

Certificates are generated using an evaluated certificate authority or hardware security module.

ISM-1324 · Certificates are generated using an evaluated certificate authority or hardware security m

Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for priv...

MAS-TRM-Access-Cryptography-Network-Security-Chapters-9-10-MFA-PKI-Encryption-Network-Segmentation · MAS TRM Access Control + Cryptography + Network + Chapters 9-10 + MFA + PKI + Encryption + Network Segmentation

Apply NZISM Chapters 6 (Personnel Security) + 7 (Physical Security) + Communications Security Chapters covering: personnel security clearances per NZSIS investigation (CONFIDENTIAL + SECRET + TOP SECRET) + clearance reviews every 5 years + need-to-know princip...

NZISM-3 · Personnel Security, Physical Security, and Cryptography

Implement cryptography + protocol security + PKI per O-RAN WG11 Security Requirements covering TLS + SSH + IPsec + certificate lifecycle.

ORANWG11-3 · Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

Questions people ask about certificate authority

What is Certificate Authority?
A trusted entity that issues digital certificates used to verify the identity of individuals, organisations, or devices. Certificate Authorities form the basis of the Public Key Infrastructure (PKI) trust model.
Why is Certificate Authority important for compliance?
Certificate Authority is a key concept in Information Security. Understanding certificate authority helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Certificate Authority?
Certificate Authority appears in the requirement text of Australian Information Security Manual, Monetary Authority of Singapore Technology Risk Management Guidelines, New Zealand Information Security Manual (NZISM), O-RAN WG11 Security Specification. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Certificate Authority?
Explore our compliance framework pages to see how certificate authority applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Certificate Authority applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.