18.11.2012 Views

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

Raytheon Company Public Key Infrastructure (PKI) Certificate Policy

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

If a formal clearance or other check is the basis for background check, the background refresh<br />

shall be in accordance with the corresponding formal clearance or other check. Otherwise, the<br />

background check shall be refreshed every ten years.<br />

One way to meet these requirements of this section is to have a national agency security<br />

clearance that is based on a five year background investigation. As an example, a successfully<br />

adjudicated United States National Agency Check with Written Inquires (NACI) or United States<br />

National Agency Check with Law Enforcement Check (NACLC) on record is deemed to have<br />

met the requirements of this section.<br />

Practice Note: Interim clearance is not sufficient because the <strong>Raytheon</strong> <strong>PKI</strong> shall not assume risk in the<br />

event the interim clearance may be revoked.<br />

Practice Note: If the person has been in the work-force less than five years, the employment verification<br />

shall consist of the periods during which the person has been in the work-force.<br />

5.3.3 Training Requirements<br />

All personnel performing duties with respect to the operation of a CA, CSA or a RA shall receive<br />

comprehensive training. Training shall be conducted in the following areas:<br />

� CA/CSA/RA security principles and mechanisms<br />

� All <strong>PKI</strong> software versions in use on the CA system<br />

� All <strong>PKI</strong> duties they are expected to perform<br />

� Disaster recovery and business continuity procedures.<br />

5.3.4 Retraining Frequency and Requirements<br />

All personnel performing duties with respect to the operation of a CA, CSA or a RA shall be<br />

aware of changes in the CA, CSA, or RA operations, as applicable. Any significant change to<br />

the operations shall have a training (awareness) plan, and the execution of such plan shall be<br />

documented. Examples of such changes are CA software or hardware upgrade, RA software<br />

upgrades, changes in automated security systems, and relocation of equipment.<br />

5.3.5 Job Rotation Frequency and Sequence<br />

No stipulation.<br />

5.3.6 Sanctions for Unauthorized Actions<br />

The RPMA shall take appropriate administrative and disciplinary actions against personnel who<br />

violate one or more of the policies in this CP.<br />

5.3.7 Independent Contractor Requirements<br />

Contractors shall not be allowed to perform functions on the <strong>Raytheon</strong> CAs. All administrators,<br />

officers, and audit administrators must be <strong>Raytheon</strong> employees. Contractors shall be allowed to<br />

perform RA and Trusted Agent roles. Contractor personnel employed to perform functions<br />

pertaining to the <strong>Raytheon</strong> <strong>PKI</strong> shall meet applicable requirements set forth in this CP (e.g., all<br />

requirements of Section 5.3).<br />

5.3.8 Documentation Supplied To Personnel<br />

The CA and CSA shall make available to its personnel the certificate policies they support, the<br />

CPS, and any relevant statutes, policies or contracts. Other technical, operations, and<br />

48 7/25/2011

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!