RON RON Technology Requirements and Security 2 — Questions and Answers
Question 1: What is a 'digital certificate' used for in the context of RON electronic notarial seals?
- A cryptographic credential issued by a certificate authority that authenticates the notary's identity and validates their electronic seal (Correct answer)
- A PDF document certifying that the notary has completed RON training
- A government-issued card that stores the notary's electronic signature on a chip
- A receipt generated by the RON platform confirming the notarization occurred
Correct answer: A cryptographic credential issued by a certificate authority that authenticates the notary's identity and validates their electronic seal
A digital certificate is a cryptographic credential issued by a trusted certificate authority that binds the notary's identity to their electronic seal, ensuring its authenticity and integrity.
Question 2: What is 'public key infrastructure' (PKI) and why is it relevant to RON?
- A framework of cryptographic technology that enables secure digital signing and verification of electronic notarial acts (Correct answer)
- A government network that stores all notarized documents in a public registry
- A platform feature that allows multiple notaries to share login credentials
- An internet protocol that encrypts only the video portion of a RON session
Correct answer: A framework of cryptographic technology that enables secure digital signing and verification of electronic notarial acts
PKI provides the cryptographic framework that enables electronic signatures and seals in RON to be verified as authentic, untampered, and traceable to a specific commissioned notary.
Question 3: What does it mean for a RON platform to maintain 'data residency' requirements?
- Storing session recordings and documents on servers located within specified geographic boundaries, often within the U.S. (Correct answer)
- Requiring the notary and signer to be physically located in the same state
- Storing data only on the notary's personal computer rather than cloud servers
- Requiring all data to be printed and stored as paper records within 24 hours
Correct answer: Storing session recordings and documents on servers located within specified geographic boundaries, often within the U.S.
Data residency requirements mandate that sensitive RON session data, including recordings and documents, be stored on servers within specified geographic boundaries to comply with state and federal privacy laws.
Question 4: What cybersecurity risk is most directly addressed by requiring multi-factor authentication (MFA) for notary logins to RON platforms?
- Unauthorized access to the notary's account by bad actors using stolen credentials (Correct answer)
- The signer accessing the notary's document queue without permission
- Platform outages caused by denial-of-service attacks
- Interception of the audio-visual feed during the session
Correct answer: Unauthorized access to the notary's account by bad actors using stolen credentials
MFA protects the notary's platform account from unauthorized access by requiring a second verification factor beyond just a password, preventing credential-theft attacks.
Question 5: What is the significance of a RON platform receiving SOC 2 Type II certification?
- It demonstrates that the platform has undergone an independent audit verifying its security, availability, and data integrity controls over time (Correct answer)
- It certifies that the platform is licensed to operate in all 50 states
- It means the platform charges a standard fee approved by the federal government
- It indicates the platform exclusively serves financial institutions
Correct answer: It demonstrates that the platform has undergone an independent audit verifying its security, availability, and data integrity controls over time
SOC 2 Type II certification is an independent security audit that verifies a platform's controls around security, availability, processing integrity, confidentiality, and privacy over a defined period, providing assurance to users.
Question 6: What technical standard governs how electronic signatures are attached to documents in RON transactions to ensure long-term verifiability?
- PAdES (PDF Advanced Electronic Signatures) standard embedded in PDF/A documents (Correct answer)
- HTML5 digital signing protocol
- SMTP secure attachment standard
- JPEG2000 image signature embedding
Correct answer: PAdES (PDF Advanced Electronic Signatures) standard embedded in PDF/A documents
PAdES is the electronic signature standard used in PDF/A documents for RON transactions, designed to remain verifiable over long periods even after signing certificates expire.
What is a 'digital certificate' used for in the context of RON electronic notarial seals?