What policy documents does EN 319 401 expect?
EN 319 401 V3.1.1 requires the TSP to specify the set of policies and practices appropriate for the trust services it provides. Those policies and practices have to be approved by management, published, and communicated to employees and external parties as relevant.
The core document is the trust service practice statement. EN 319 401 requires it to describe the practices and procedures used to address the applicable trust service policy identified by the TSP, identify obligations of external organizations supporting the service, and be maintained through a defined review process. The standard does not mandate a particular practice-statement structure.
- Maintain a trust service practice statement that maps the applicable trust service policy to the practices and procedures actually used.
- Record management approval and final authority for approving the practice statement.
- Identify external organizations supporting the service and the policies or practices that apply to their obligations.
- Define responsibilities for maintaining the practice statement and reviewing it over time.
Primary ETSI source for EN 319 401 policy and practice statement requirements.