Ariz. Admin. Code § 2-12-501

Current through Register Vol. 30, No. 18, May 3, 2024
Section R2-12-501 - Definitions

A. "Acceptable Certification Authorities" means authorities that meet the requirements of R2-12-504.

B. "Approved List of Certification Authorities" means the list of Certification Authorities approved by the Secretary of State to issue certificates for electronically signed transactions involving public entities in Arizona.

C. "Asymmetric crypto-system" means an electronically processed algorithm, or series of algorithms, which uses two different keys with the following characteristics:

1. One key encrypts a given message;

2. One key decrypts a given message; and

3. The keys have the property that it is infeasible to discover one key from merely knowing the other key.

D. "CARAT Guidelines" means the CARAT Guidelines - Guidelines for Constructing Policies Governing the Use of Identity-Based Public Key Certificates drafted by the Certification Authority Rating and Trust (CARAT) Task Force of the National Automated Clearing House Association (NACHA), Version 1 Draft, September 21, 1998, excluding later amendments or additions, incorporated by reference and on file with the Secretary of State.

E. "Certificate" means an electronic document attached to a public key by a trusted certification authority, which provides proof that the public key belongs to a legitimate subscriber and has not been compromised.

F. "Certification Authority" means a person or entity that issues a certificate.

G. "Electronically signed communication" means an electronic message that has been processed in such a manner that the message is tied to the individual who signed the message.

H. "GITA" means the Government Information Technology Agency, as established by A.R.S. § 41-3501.

I. "Key pair" means a private key and its corresponding public key in an asymmetric crypto-system. The key pair is unique in that the public key can verify a digital signature that the private key creates.

J. "Message" means an electronic representation of information intended to serve as a written communication with a public entity.

K. "Person" means a human being or any organization capable of signing a document, either legally or as a matter of fact.

L. "Policy Authority" means, as defined by CARAT Guidelines, some authoritative party that formulates the guidelines defining the process of electronic signature use.

M. "Private key" means the key of a key pair used to create a digital signature.

N. "Public key" means the key of a key pair used to verify a digital signature.

O. "Public entity" means any budget unit, as defined in A.R.S. § 41-3501.

P. "S.A.S. 70" means the standards set in the American Institute of Certified Public Accounts (AICPA) Statement on Auditing Standards No. 70. Should current S.A.S. 70 standards (or any succeeding version) be superceded, the Secretary of State, in consultation with GITA and the State Treasurer, shall establish a deadline for all affected parties to comply with the replacing standard. This deadline shall be no later than two years from the date of issuance of the new S.A.S. standards. GITA will also provide a "roadmap" of how the revised standard fits the current Type 1 and Type 2 S.A.S. 70 designations used elsewhere in these rules.

Q. "Subscriber" means a person who:

1. Is the subject listed in a certificate,

2. Accepts the certificate, and

3. Holds a private key which corresponds to a public key listed in that certificate.

Ariz. Admin. Code § R2-12-501

Adopted by exempt rulemaking at 5 A.A.R. 742, effective February 19, 1999 (Supp. 99-1).