Tất cả nhân viên của tổ chức phải được đào tạo trong các thủ tục để xử lý các thông tin mà họ được phép truy cập. Tùy ý và kỹ thuật kiểm soát truy cập bắt buộc sử dụng phân loại như là một phương pháp để xác định những người có thể truy cập vào những nguồn lực. | SY0 - 201 not actually been revoked the original keys and certificate can be used to provide the necessary authentication information and proof of identity for the renewal phase. Revocation A certificate can be revoked when its validity needs to be ended before its actual expiration date is met and this can occur for many reasons for example a user may have lost a laptop or a smart card that stored a private key an improper software implementation may have been uncovered that directly affected the security of a private key a user may have fallen victim to a social engineering attack and inadvertently given up a private key data held within the certificate may no longer apply to the specified individual or perhaps an employee left a company and should not be identified as a member of an in-house PKI any longer. In the last instance the certificate which was bound to the user s key pair identified the user as an employee of the company and the administrator would want to ensure that the key pair could not be used in the future to validate this person s affiliation with the company. Revoking the certificate does this. If any of these things happen a user s private key has been compromised or should no longer be mapped to the owner s identity. A different individual may have access to that user s private key and could use it to impersonate and authenticate as the original user. If the impersonator used the key to digitally sign a message the receiver would verify the authenticity of the sender by verifying the signature by using the original user s public key and the verification would go through perfectly the receiver would believe it came from the proper sender and not the impersonator. If receivers could look at a list of certificates that had been revoked before verifying the digital signature however they would know not to trust the digital signatures on the list. Because of issues associated with the private key being compromised revocation is permanent and final