Preliminary Recommendations (continued…)
3. Examine current and draft e-Business policies to ensure that the use of non-DoD PKI alternatives is addressed appropriately, considering both pros and cons. This means to both encourage and discourage use as appropriate.
- Functional communities should explicitly identify their assurance requirements in their associated e-Business policies.
- The appropriate e-Business policy should be updated or appended to include such requirements
- Consider modifying the November 2, 200 Draft ASD (C3I) PKE policy to incorporate an examination of the relying party assurance levels required for applications within DoD for external and non DoD class 4 certificates. Consider requiring business case analyses to ensure that relying party assurance requirements. Additionally, this process should be defined and explained in the policy