(2) Without prejudice to the generality of the subsection (1), regulations may provide for:___
(a) safety, control, or management of keys, passwords or other secret information relating to
use of services of accredited certification service providers;
(b) standards, procedures and practices for time and date stamping;
(c) minimum qualifications of staff of accredited certification service providers;
(d) adequacy of facilities and equipment for secure and reliable operation;
(e) privacy and protection of data of subscribers;
(f) inspection of operations;
(g) crosscertifications, accreditation, recognition, bridge certification or other arrangements
with certification service providers based in other countries;
(h) development of certification management system;
(i) reparation to subscribers for damage arising from negligence of certification service
provider with conditions for and limits to liability;
(j) identification of areas of commerce or governance for use of certificates;
(k) standardization and technology relating to protocols, algorithm., interpretability of
systems, applications and infrastructure for accredited certification service providers;
(l) form and contents of applications for accreditation;
(m) suspension or revocation of certification;
(n) suspension or revocation of accreditation;
(o) certificate profiles with mandatory and optional fields and extension fields, if any;
(p) certificate revocation and suspension list profiles with mandatory and optional fields, and
extension fields (if any);
(q) retention of records by certification authorities and the repository;
(r) recommended code of practice for handling and storage of business information and
records in electronic form; and
(s) regulation of access and audit trails.
Page 19 of 21