Closed Bug 1990277 Opened 11 months ago Closed 4 months ago

SwissSign: recommendation on CA-specific risk assessment

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: sandy.balzer, Assigned: sandy.balzer)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident description: The audit report contains a recommendation regarding the improvement of SwissSign’s risk assessment process to better assess risks specific to certification authority related operations.

  • Relevant policies: CA/B-F TLS BR, 5

  • Source of incident disclosure: Audit

Assignee: nobody → sandy.balzer
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000049
  • Incident description: The audit report contains a recommendation regarding the improvement of SwissSign’s risk assessment process to better assess risks specific to certification authority related operations.
  • Timeline summary:
    • Non-compliance start date: N/A (audit recommendation and not non-compliance)
    • Non-compliance identified date: N/A (audit recommendation and not non-compliance)
    • Non-compliance end date: N/A (audit recommendation and not non-compliance)
  • Relevant policies: CA/B-F TLS BR, 5
  • Source of incident disclosure: Audit

Impact

  • Total number of certificates: N/A
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: N/A
  • Incident heuristic: N/A
  • Was issuance stopped in response to this incident, and why or why not?: Certificate issuance was not halted, as certificate issuance was not impacted.
  • Analysis: N/A
  • Additional considerations: SwissSign conducts risk assessments as required per regulation. The risk assessments are asset based, meaning that for each asset in scope, the risk is evaluated and mitigation measures, risk avoidance, transfer or acceptance are defined, documented and regularly reviewed.

Timeline

  • 12.09.2025 Audit report containing this recommendation published

Related Incidents

none found

Root Cause Analysis

Contributing Factor #1:

  • Description: Auditors recommend to also consider process/operations based risks (i.e. end-to-end view of a process to determine the process risk).
  • Timeline: N/A
  • Detection: Audit
  • Interaction with other factors: N/A
  • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A
  • What didn’t go well: N/A
  • Where we got lucky: N/A
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Perform process/operations risk assessment for CA related processes and operations Prevent Root Cause # 1 Risk assessments documented 2026-04-30 In progress

Appendix

N/A

We're monitoring this Bugzilla for Community feedback.

We're monitoring this Bugzilla for Community feedback.

Whiteboard: [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding] Next update 2026-04-30

Update

Summary

We have completed below action item.

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Perform process/operations risk assessment for CA related processes and operations Prevent Root Cause # 1 Risk assessments documented 2026-04-29 done

Appendix

N/A

Report Closure Summary

  • Incident Description:
    An ETSI audit report for SwissSign included a recommendation to enhance the existing risk assessment approach by explicitly considering process- and operations-based risks related to certification authority activities.

  • Incident Root Cause(s):
    The audit identified that SwissSign’s risk assessments were primarily asset-based and did not explicitly include an end-to-end, process/operations-focused risk perspective for CA-related processes.

  • Remediation Description:
    SwissSign performed a comprehensive process and operations risk assessment covering CA-related processes, incorporating an end-to-end view. The identified risks, mitigations, and acceptance criteria were documented and integrated into the existing risk management framework.

  • Commitment Summary:
    All action items associated with this recommendation have been completed, and SwissSign has integrated process/operations-based risk assessments into its ongoing risk management activities.

SwissSign will continue monitoring this Bugzilla for Community feedback.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-05-07.

Whiteboard: [ca-compliance] [audit-finding] Next update 2026-04-30 → [close on 2026-05-07] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 4 months ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-05-07] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.