Skip to content

NS-009: Permit Log Storage Systems to be operated in Third Party-Controlled Environments - #59

Open
CBonnell wants to merge 16 commits into
mainfrom
log-storage-system-in-cloud
Open

NS-009: Permit Log Storage Systems to be operated in Third Party-Controlled Environments#59
CBonnell wants to merge 16 commits into
mainfrom
log-storage-system-in-cloud

Conversation

@CBonnell

Copy link
Copy Markdown
Member

No description provided.

Comment thread docs/NSR.md Outdated
Comment thread docs/NSR.md Outdated
Comment thread docs/NSR.md Outdated
Comment thread docs/NSR.md Outdated
Comment thread docs/NSR.md Outdated
Corey Bonnell and others added 3 commits April 21, 2026 12:08
Comment thread docs/NSR.md Outdated
Comment thread docs/NSR.md Outdated
Comment thread docs/NSR.md
@CBonnell
CBonnell marked this pull request as ready for review April 30, 2026 16:33
@CBonnell
CBonnell requested a review from a team as a code owner April 30, 2026 16:33
@CBonnell CBonnell changed the title NS-XX: Permit Log Storage Systems to be operated in "cloud" environments NS-009: Permit Log Storage Systems to be operated in "cloud" environments Apr 30, 2026
@CBonnell CBonnell changed the title NS-009: Permit Log Storage Systems to be operated in "cloud" environments NS-009: Permit Log Storage Systems to be operated in Third Party-Controlled Environments Apr 30, 2026
Comment thread docs/NSR.md
* Security Support System.
* Root CA System (Air-Gapped and otherwise);
* Security Support System; or
* Logging System.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm concerned that some interpretation may take the Logging System that is in a Third-Party Environment as a system in scope that needs to meet all the NSR requirements 1-4. This would be difficult as you'll need to validate/audit the Third Party Controlled Environment itself.

Some alternative options:

  1. Could we break out the logging system from CA Infrastructure and define the requirements for logging system comprehensively separately in section 5/section 6 respectively?
  2. Update each requirement section where "CA Infrastructure" is referenced to "CA Infrastructure in a CA Controlled Environment"

Comment thread docs/NSR.md

Logging Systems MUST be in:

1. a CA-Controlled Environment;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If it is in a CA-controlled environment, what requirements must the logging system follow?

Comment thread docs/NSR.md

## 6.1 Risk Assessment

The CA MUST perform a risk assessment of the service provider of the Third Party-Controlled Environment. The risk assessment MUST cover topics applicable to the services being used and MUST cover the CA’s considerations and criteria. The CA MUST document the evidence relied upon in performing the risk assessment, which MAY include independently audited or certified reports. The risk assessment SHOULD cover:

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are there a common criterion/standard for when a risk is acceptable or not acceptable. If it becomes unacceptable, is there a timeline to remediate?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants