ДСТУ ETSI TS 119 461:2026 Электронные подписи и инфраструктуры (ESI). Требования по политике и безопасности для компонентов доверительных услуг, обеспечивающих проверку личности субъектов доверительных услуг...
ДСТУ ETSI TS 119 461:2026
(ETSI TS 119 461 V2.1.1
(2025-02), IDT)
Електронні підписи та інфраструктури (ESI). Вимоги щодо
політики та безпеки для
компонентів довірчих послуг, що забезпечують перевіряння
особи суб’єктів довірчих послуг
Не є офіційним виданням.
Офіційне видання розповсюджує національний орган стандартизації
(ДП «УкрНДНЦ» http://uas.gov.ua)
Contents
Intellectual Property Rights
Foreword
Modal verbs terminology
Introduction
1 Scope
2 References
2.1 Normative references
2.2 Informative references
3 Definition of terms, symbols, abbreviations and notations
3.1 Terms
3.2 Symbols
3.3 Abbreviations
3.4 Notations
4 General concepts
4.1 Identity proofing actors
4.2 Identity proofing process
4.3 Identity proofing context
4.4 Authoritative evidence and supplementary evidence
4.5 Consideration of threats
4.6 Identity proofing service policy
5 Operational risk assessment
6 Policies and practices
6.1 Identity proofing service practice statement
6.2 Terms and Conditions
6.3 Information security policy
7 Identity proofing service management and operation
7.1 Internal organization
7.2 Human resources
7.3 Asset management
7.4 Access control
7.5 Cryptographic controls
7.6 Physical and environmental security
7.7 Operation security
7.8 Network security
7.9 Vulnerabilities and incident management
7.10 Collection of evidence
7.11 Business continuity management
7.12 Termination and termination plans
7.13 Compliance
7.14 Supply chain
8 Identity proofing service requirements
8.1 Initiation
8.2 Attribute and evidence collection
8.2.1 General requirements
8.2.2 Attribute collection
8.2.2.1 Attribute collection for natural person
8.2.2.2 Attribute collection for legal person
8.2.2.3 Attribute collection for natural person representing legal person
8.2.3 Use of physical or digital identity document as evidence
8.2.4 Use of existing eID means as evidence
8.2.5 Use of existing digital signature means as evidence
8.2.6 Use of trusted register as supplementary evidence
8.2.7 Use of proof of access as supplementary evidence
8.2.8 Use of documents and attestations as supplementary evidence
8.2.9 Evidence collection for natural person representing legal person
8.3 Attribute and evidence validation
8.3.1 General requirements
8.3.2 Validation of digital identity document
8.3.3 Validation of physical identity document
8.3.4 Validation of eID means
8.3.5 Validation of digital signature with certificate
8.3.6 Validation of trusted registers
8.3.7 Validation of proof of access
8.3.8 Validation of documents and attestations
8.4 Binding to applicant
8.4.1 General requirements
8.4.2 Capture of face image of the applicant
8.4.3 Binding to applicant by automated face biometrics
8.4.4 Binding to applicant by manual face verification
8.4.5 Binding to applicant for legal person and natural person representing legal person
8.5 Issuing of proof
8.5.1 Result of the identity proofing
8.5.2 Evidence of the identity proofing process
9 Use cases for identity proofing to Baseline and Extended LoIP
9.1 Introduction, compliance with the present document, general requirements for all use cases
9.2 Use cases for identity proofing of natural person
9.2.1 Use cases using an identity document with physical presence of the applicant
9.2.1.1 General requirements
9.2.1.2 Use case for manual operation
9.2.1.3 Use case for hybrid manual and automated operation
9.2.1.4 Use case for automated operation
9.2.2 Use cases using an identity document for attended remote identity proofing
9.2.2.1 General requirements
9.2.2.2 Use case for manual operation (Baseline LoIP only)
9.2.2.3 Use case for hybrid manual and automated operation
9.2.3 Use cases using an identity document for unattended remote identity proofing
9.2.3.1 General requirements
9.2.3.2 Use case for manual operation (Baseline LoIP only)
9.2.3.3 Use case for hybrid manual and automated operation
9.2.3.4 Use case for automated operation
9.2.4 Use case for identity proofing by authentication using eID means
9.2.5 Use case for identity proofing using digital signature with certificate
9.3 Use case for identity proofing of legal person
9.4 Use case for identity proofing of natural person representing legal person
9.5 Use cases for additional identity proofing to enhance an identity proven by use of an eID from Baseline LoIP to Extended LoIP
9.5.1 General requirements
9.5.2 Use case for enhancing identity proofing to Extended LoIP by a full identity proofing using an identity document
9.5.3 Use case for enhancing identity proofing to Extended LoIP by use of a previously captured reference face image
Annex A (informative): Void
Annex B (informative): Threats to identity proofing
Annex C (normative): Use cases for identity proofing for EU qualified trust services
C.1 Introduction
C.2 Use cases for issuing of qualified certificate according to Article 24.1 of the original eIDAS regulation
C.2.1 Use case for identity proofing by physical presence of the applicant
C.2.2 Use case for identity proofing by authentication using eID means
C.2.3 Use case for identity proofing by certificate of qualified electronic signature or qualified electronic seal
C.2.4 Use case for identity proofing by other identification means
C.2.5 Use case for identity proofing of legal person
C.2.6 Use case for identity proofing of natural person representing legal person
C.3 Use cases for issuing of qualified certificate or qualified electronic attestation of attributes according to Article 24.1, 24.1a, and 24.1b of the amended eIDAS regulation
C.3.1 Use case for identity proofing by physical presence of the applicant
C.3.2 Use case for identity proofing by authentication using eID means
C.3.3 Use case for identity proofing by certificate of qualified electronic signature or qualified electronic seal
C.3.4 Use case for identity proofing by other identification means
C.3.5 Use case for identity proofing of legal person
C.3.6 Use case for identity proofing of natural person representing legal person
C.4 Use case for qualified electronic registered delivery services according to Article 44 of the amended eIDAS regulation
Annex D (informative): Mapping to applicable requirements of the amended eIDAS regulation
History
Полная версия документа доступна в тарифе «ВСЕ ВКЛЮЧЕНО».



