Trustis Ltd Audit Statement 2017
Categories
(CA Program :: CA Documents, task)
Tracking
(Not tracked)
People
(Reporter: blake.morgan, Assigned: kathleen.a.wilson)
Details
(Whiteboard: [ca-audits])
Attachments
(2 files, 10 obsolete files)
| Assignee | ||
Comment 1•8 years ago
|
||
| Reporter | ||
Comment 2•7 years ago
|
||
| Reporter | ||
Comment 3•7 years ago
|
||
| Assignee | ||
Comment 4•7 years ago
|
||
| Reporter | ||
Comment 5•7 years ago
|
||
| Reporter | ||
Comment 6•7 years ago
|
||
| Reporter | ||
Comment 7•7 years ago
|
||
| Assignee | ||
Comment 8•7 years ago
|
||
| Assignee | ||
Updated•7 years ago
|
| Reporter | ||
Comment 9•7 years ago
|
||
| Assignee | ||
Comment 10•7 years ago
|
||
| Reporter | ||
Comment 11•7 years ago
|
||
| Reporter | ||
Comment 12•7 years ago
|
||
Audit Statement for Trustis FPS Rooot CA for period of 17 Feb 2018 to 16 Jan 2019.
| Reporter | ||
Comment 13•6 years ago
|
||
This is the current ETSI EN 311 401 and EN 311 411-1 Audit Statement for the Trustis PFS Root
| Reporter | ||
Comment 14•6 years ago
|
||
This is the new ETSI EN 319 401 and EN 319411-1 audit statement for the Trustis FPS Root CA
| Reporter | ||
Comment 15•6 years ago
|
||
| Reporter | ||
Comment 16•6 years ago
|
||
This is the correct version of the Audit Statement as provided by LRQA.
| Reporter | ||
Comment 17•5 years ago
|
||
Following enquiries with the Audit body and root cause analysis regarding why there was confusion regarding Audit Coverage dates, this has now been resolved. Updated Audit Verification Certificate has been uploaded to this bug.
Incident report to follow in https://bugzilla.mozilla.org/show_bug.cgi?id=1623472
Comment 18•5 years ago
|
||
Kathleen: I wasn't sure, have you previously confirmed that LRQA is an appropriate auditor?
UKAS is the NAB for the UK, and while Lloyd's Register Quality Assurance is a CAB, I'm having trouble seeing how their accredited scope includes this, and/or how it meets the requirements set forth in ETSI EN 319 403.
LRQA is scoped against ISO/IEC 27001:2013 (ISMS) and ISO/IEC 20000-1:2011 and 2018 (ITSMS), but the ETSI standards are based on ISO 17065. Trustis is not using a qualified/notified scheme (which is only the GOV.uk eID scheme, AFAICT), so there's also that angle.
As it stands, based on the information provided by UKAS, I'm having trouble seeing how this auditor meets Section 8.2 of the Baseline Requirements:
(For audits conducted in accordance with any one of the ETSI standards) accredited in accordance with ISO 17065 applying the requirements specified in ETSI EN 319 403;
Comment 19•5 years ago
|
||
| Assignee | ||
Comment 20•5 years ago
|
||
(In reply to Ryan Sleevi from comment #18)
Kathleen: I wasn't sure, have you previously confirmed that LRQA is an appropriate auditor?
Yes, but looking back through my email, I see that was in 2015, and I did not find evidence of re-checking this auditor's qualifications. I'll add that to my to-do list -- to recheck the qualifications of previously verified auditors.
Updated•3 years ago
|
Updated•3 years ago
|
Description
•