21 Code For Federal Regulation Parts 1305, 1311 Page 64

ADVERTISEMENT

(b) A system used to digitally sign Schedule I or II orders must meet the following
requirements:
(1) The cryptographic module must be FIPS 140-2, Level 1 validated.
(2) The digital signature system and hash function must be compliant with FIPS 186-2
and FIPS 180-2.
(3) The private key must be stored on a FIPS 140-2 Level 1 validated cryptographic
module using a FIPS-approved encryption algorithm.
(4) The system must use either a user identification and password combination or
biometric authentication to access the private key. Activation data must not be displayed as they
are entered.
(5) The system must set a 10-minute inactivity time period after which the certificate
holder must reauthenticate the password to access the private key.
(6) For software implementations, when the signing module is deactivated, the system
must clear the plain text private key from the system memory to prevent the unauthorized access
to, or use of, the private key.
(7) The system must be able to digitally sign and transmit an order.
(8) The system must have a time system that is within five minutes of the official
National Institute of Standards and Technology time source.
(9) The system must archive the digitally signed orders and any other records required in
Part 1305 of this chapter, including any linked data.
(10) The system must create an order that includes all data fields listed under
§ 1305.21(b) of this chapter.
64

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Legal