12 Guidelines for other agencies
-
This section offers guidelines for agencies that have personnel with access to a PKT-enabled application, e.g. other agencies' access to the Treasury's CFISnet application.
-
Personnel need to be educated about the use of digital certificates. Agencies may wish to make use of the S.E.E. Project's digital certificate policy that guides staff in their use of digital certificates, e.g. when to digitally sign, and what they may encrypt.
-
Agencies need not be restricted to the tokens and CAs recommended by the application owner, e.g. CFISnet could be configured to use a high-grade certificate from a different CA, but this must be agreed with the application owner.
-
The agency should update its procedures for staff departure to ensure that individuals' certificates are revoked when they leave the organisation.
[ Previous | Next ]

