Skip to content

Commit

Permalink
fix: cabforum#387 Remove Section 8.4 reference to triennial audit
Browse files Browse the repository at this point in the history
  • Loading branch information
XolphinMartijn committed Oct 23, 2024
1 parent f4cbb7c commit ee7fef4
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion docs/BR.md
Original file line number Diff line number Diff line change
Expand Up @@ -3516,7 +3516,7 @@ The audit MUST be conducted by a Qualified Auditor, as specified in [Section 8.2

For Delegated Third Parties which are not Enterprise RAs, then the CA SHALL obtain an audit report, issued under the auditing standards that underlie the accepted audit schemes found in [Section 8.4](#84-topics-covered-by-assessment), that provides an opinion whether the Delegated Third Party's performance complies with either the Delegated Third Party's practice statement or the CA's Certificate Policy and/or Certification Practice Statement. If the opinion is that the Delegated Third Party does not comply, then the CA SHALL not allow the Delegated Third Party to continue performing delegated functions.

The audit period for the Delegated Third Party SHALL NOT exceed one year (ideally aligned with the CA's audit). However, if the CA or Delegated Third Party is under the operation, control, or supervision of a Government Entity and the audit scheme is completed over multiple years, then the annual audit MUST cover at least the core controls that are required to be audited annually by such scheme plus that portion of all non-core controls that are allowed to be conducted less frequently, but in no case may any non-core control be audited less often than once every three years.
The audit period for the Delegated Third Party SHALL NOT exceed one year (ideally aligned with the CA's audit).

## 8.5 Actions taken as a result of deficiency

Expand Down

0 comments on commit ee7fef4

Please sign in to comment.