Need Technical Support?
X
Please type your technical question in the search box below:
Loading Customer Support
close
Proper Signatures, Proven Solutions

CoSign Digital Signatures for Government Organizations - Regulatory Compliance

OverviewBusiness CaseFeatures & TechnologyRegulatory ComplianceCustomers

Digital Signatures Legal Compliance

GSA Schedule

Digital signature solutions enable the creation of compliant and legally enforceable electronic records, eliminating an organization's need to print documentation for signature authorizations. This reality allows organizations to enjoy the benefits of a truly automated workflow, which includes the replacement of slow and expensive paper-based approval processes with fast, low-cost, and fully digital ones.

CoSign Central stores the signing key (Private Key) in a centralized and secure hardware device (The CoSign FIPS version is FIPS-140-2 Level 3 certified), ensuring that any tampering attempt with the secured CoSign appliance will be detectable. The strong key security combined with a high level of user identification (supported by standard operating procedures for identification throughout the employee recruitment process) enables CoSign to comply with the most stringent federal, state, and government regulatory requirements including ESIGN, UETA, the Government Paperwork Elimination Act, the Digital Signature And Electronic Authentication Law, and SOX.

In recent years, most countries worldwide have adopted legislation and regulations that recognize the legality of a digital signature (standard electronic signatures) and deem it a binding signature. In addition to governments, many industries have established regulations that define digital signatures as a replacement for handwritten signatures.


Read more:


GSC Award 2009

Global Security Challenge Award 2009

ARX is the winner of the 2009 Best Security SME Category of the Global Security Challenge America West Regional Finals.


Legislation

 

Related Legislation on Digital Signatures in the US and Worldwide


Industry Regulations and Standards

 


CoSign Certifications for Digital Signature Directives

CoSign also follows the internationally approved Common Criteria security standard (ISO/IEC 15408) by using smartcards that are Common Criteria CWA 14169 certified within the CoSign hardware enclosure. The Common Criteria SSCD validation provides compliance with EU Electronic Signature Directives (European Union Directive 1999/93/EC on Electronic Signature).

Typical Legislation Requirements for Digital Signature Directives

Digital signature regulations vary from country to country. Taking the European Electronic Signature Directive (EC Directive 99/93 on Electronic Signatures) as an example, the requirements for a standard (advanced) Electronic Signature are:

  • It is uniquely linked to the signatory. 
  • The signature-creation-data used for signature generation cannot, with reasonable assurance, be derived, and the signature is protected against forgery using currently available technology.
  • It is created using means that the signatory can maintain under his sole control.
  • It is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable.

Is CoSign a Secure Signature Creation Device (SSCD)?

The European Directive (EC Directive 99/93 on Electronic Signatures) defines SSCD as:

  1. Secure signature-creation devices must, by appropriate technical and procedural means, ensure:
    • The signature-creation-data used for signature generation can practically occur only once, and that their secrecy is reasonably assured.
    • The signature-creation-data used for signature generation cannot, with reasonable assurance, be derived and the signature is protected against forgery using currently available technology. 
    • The signature-creation data used for signature generation can be reliably protected by the legitimate signatory against the use of others.
  2. Secure signature-creation devices must not alter data to be signed or prevent such data from being presented to the signatory prior to the signature process.

CoSign complies with the SSCD requirements defined by the EU electronic signature directive in the following ways:

    • CoSign is available as FIPS 140-2 level 3 validated for those EU member states requiring such a certification for SSCD devices. 
    • The CoSign SSCD model includes CWA approved smartcards for EU member states requiring this specific certification for SSCD devices.

CoSign in Gov’t Entities

Want to try CoSign Central or Cloud
for free?