Certificate Practice Statements
Beyond the limits of physical and logical protection of keys used to sign certificates, CA policies and procedures are clearly spelled out in Certificate Practice Statements (CPS). These cover those human factors mentioned earlier in the series. CPSs consist of detailed descriptions of certificate policies are how they''re implemented by a particular CA.
The American Bar Association defines them this way:
"A CPS is a statement of the practices which a certification authority employs in issuing certificates."
When CAs negotiate cross certification services, they''ll examine and compare each other''s CPS. The liability that certificate issuers and end entities assume plays a role in the degrees of trust.
X.509 certificates contain certificate policies that allows certificate holders to decide how much trust to place in their certificates. According to X.509, Version 3, a CPS is:
"A named set of rules that indicates the applicability of a certificate to a particular community and/or class of application with common security requirements."