Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: tmkuo, Assigned: tmkuo)
Details
(Whiteboard: [ca-compliance] [audit-finding] )
Preliminary Incident Report
Summary
- Incident description: During the audit period, no objective evidence was found regarding GTLSCA's audit and evaluation for third parties.
- Relevant policies: WebTrust for CA V2.2.2 (Criterion 3.1.11)
Arrangements involving third party access to CA facilities and systems are based on a formal contract containing necessary security requirements.
- Source of incident disclosure: Audit
Updated•8 months ago
|
| Assignee | ||
Comment 1•7 months ago
|
||
Full Incident Report
Summary
- CA Owner CCADB unique ID: A006506
- Incident description: This WebTrust audit finding originated from an issue identified by the auditor during GTLSCA’s 2025 audit period. During the audit period, no objective evidence was found regarding GTLSCA's audit and evaluation for third parties with access to CA facilities and systems.
- Timeline summary:
- Non-compliance start date: 2024-10-01
- Non-compliance identified date: 2025-11-18
- Non-compliance end date: 2025-12-23
- Relevant policies: WebTrust for CA V2.2.2 (Criterion 3.1.11)
Arrangements involving third party access to CA facilities and systems are based on a formal contract containing necessary security requirements.
- Source of incident disclosure: Audit
Impact
- Total number of certificates: N/A
- Total number of "remaining valid" certificates: N/A
- Affected certificate types: N/A
- Incident heuristic:
(a) Incomplete inventory of third parties with access to CA environments.
(b) GTLSCA should conduct a more comprehensive risk assessment for third parties.
(c) The Auditor considers that the evaluation processes exist but are incomplete, or insufficiently documented for some third-parties vendors according to WebTrust for CA V2.2.2 Criterion. - Was issuance stopped in response to this incident, and why or why not?: As there were no certificates misissued, issuance was not stopped. However, this CA has already stopped issuing TLS certificates in early March 2025.
- Analysis:
- Additional considerations:
Timeline
All times are UTC+8.
2024-10-01
- Initiate the new annual cycle of system maintenance and related hardware and software procurement projects. [start of the non-compliance]
2025-11-18
- 17:00-18:00 GTLSCA Auditing Close Meeting. [Identify of the non-compliance]
2025-11-20
- 14:00-15:00 Internal meeting discussing the finding received and planning for the revision of evaluation and risk assessment. (GTLSCA Team and Root CA Team)
2025-12-23
- Perform a more comprehensive risk assessment of third‑party vendors. [End of the non-compliance]
Related Incidents
| Bug | Date | Description |
|---|---|---|
| [Related Bug ID](Related Bug URL) | Date Related Bug was opened | A description of how the subject Bug is related to the Bug referenced. |
Root Cause Analysis
Contributing Factor 1: Third‑Party Risk Management not fully institutionalized
- Description: Although GTLSCA has basic vendor management processes in place, a formal and comprehensive Third‑Party Risk Management framework had not been fully established. The scope, frequency, and minimum evidence requirements for evaluating third parties with access to CA facilities and systems were not clearly defined, resulting in certain vendors not being subject to mandatory assessment.
- Timeline:
2024-10-01: Initiate the new annual cycle of system maintenance and related hardware and software procurement projects.
2025-11-18: GTLSCA Auditing Close Meeting. - Detection: Findings identified during the annual audit process.
- Interaction with other factors: Although the contracts with third parties require them to sign Intellectual Property and Confidentiality. Undertakings, multiple incidents occurred within GTLSCA over the past year. As a result, the auditor determined that the assessment should have included an evaluation of the applicability and professional competence of third-party vendors. Consequently, the supporting evidence provided was not accepted by the auditor.
Contributing Factor 2: Lack of alignment between vendor inventory and access records
- Description: Vendor inventories, system access authorization records, and risk assessment documentation were maintained by different functions and were not fully synchronized. The absence of a single authoritative register mapping third parties to system or facility access led to gaps in identifying vendors requiring evaluation.
- Timeline:
2024-10-01: Initiate the new annual cycle of system maintenance and related hardware and software procurement projects.
2025-11-18: GTLSCA Auditing Close Meeting. - Detection: Findings identified during the annual audit process.
- Interaction with other factors: Inadequate monitoring mechanism: The procurement process was not effectively integrated with the compliance assessment process, resulting in failures to timely detect omitted assessment procedures prior to the audit.
Lessons Learned
- What went well: N/A
- What didn’t go well:
(a) Third parties are part of the CA trust boundary: Third parties with access to CA facilities or systems represent an extension of the CA trust boundary and must be subject to equivalent risk management and oversight controls.
(b) Risk‑based assessments improve effectiveness and efficiency: Applying a risk‑based approach allows evaluation depth and frequency to be aligned with the level of access and potential impact, ensuring compliance while optimizing resource allocation. - Where we got lucky: N/A
- Additional:
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Retrospective Third-Party Evaluation | Mitigate | Root Cause # 1 | Complete all required technical assessment and contract review records, and require full evaluations for all new contracts. | 2025-12-23 | Completed |
| Include this as an item in the internal quarterly audit | Prevent | Root Cause # 1 & 2 | Internal Quarterly Audit Plan and Review Checklist | 2025-12-23 | Completed |
| Improve compliance assessment process | Prevent | Root Cause # 2 | (a)Revise the internal control compliance assessment process and incorporate it into the Compliance Assessment checklist. (b)Develop corrective actions for non-compliant items and track the completion status of the corrective actions. | 2026-01-08 | Completed |
The delayed disclosure related to this audit finding, please refer to Bug 2009048.
| Assignee | ||
Comment 2•7 months ago
|
||
Chunghwa Telecom is monitoring this bug for comments and questions. We have no new information at the moment.
| Assignee | ||
Comment 3•7 months ago
|
||
Chunghwa Telecom is monitoring this bug for comments and questions. We have no new information at the moment.
| Assignee | ||
Comment 4•7 months ago
|
||
Report Closure Summary
-
Incident description: During the 2025 WebTrust audit cycle, the auditor identified that GTLSCA did not maintain objective evidence demonstrating adequate audit and evaluation of third‑party vendors with access to CA facilities and systems. Specifically, GTLSCA lacked a fully documented and comprehensive evaluation framework for these third parties, which resulted in incomplete assessments and insufficient evidence to meet WebTrust for CA V2.2.2 Criterion 3.1.11.
The non‑compliance period extended from 2024‑10‑01 (the annual maintenance and procurement cycle began) until 2025‑12‑23 (a complete vendor risk assessment was performed). The issue was formally identified during the 2025‑11‑18 audit close meeting. No certificates were mis‑issued as part of this incident. Since GTLSCA had already ceased TLS certificate issuance earlier in March 2025, issuance operations were not suspended.
-
Incident Root Cause(s):
(a)Third‑Party Risk Management not fully institutionalized: GTLSCA had basic vendor management practices, but lacked a formal and comprehensive third‑party risk management framework. The scope, frequency, and minimum evidence requirements for evaluating third parties with access to CA facilities and systems were not clearly defined, resulting in certain vendors not being subject to mandatory assessment.
Although the contracts with third parties require them to sign Intellectual Property and Confidentiality. Undertakings, multiple incidents occurred within GTLSCA over the past year. As a result, the auditor determined that the assessment should have included an evaluation of the applicability and professional competence of third-party vendors. Consequently, the supporting evidence provided was not accepted by the auditor.
(b)Misalignment between vendor inventory and access records: The vendor inventory, system access authorization records, and risk assessment documents were managed independently by different internal functions and were not fully synchronized. This lack of synchronization caused gaps in identifying third parties who required formal evaluation. In addition, the procurement process was not effectively integrated with the compliance assessment process, resulting in failures to timely detect omitted assessment procedures prior to the audit. -
Remediation description:
GTLSCA implemented several corrective measures:
(a)Retrospective Third‑Party Evaluation: completed a comprehensive review and technical assessment for all third‑party vendors with facility or system access, including contract validation and evidence collection. (Completed on 2025‑12‑23)
(b)Integration Into Internal Quarterly Audit: added vendor evaluation and risk assessment requirements into the internal quarterly audit plan and review checklist, ensuring continuous compliance monitoring. (Completed on 2025‑12‑23)
(c)Improvement of Compliance Assessment Processes: Revised the internal control assessment process, embedded it into the Compliance Assessment checklist, and established follow‑up procedures for non‑compliant items, including tracking corrective action closure. (Completed on 2026‑01‑08)These actions collectively eliminate the structural gaps that led to the audit finding and ensure that third‑party risk oversight aligns with WebTrust requirements.
-
Commitment summary: GTLSCA had implemented some measures to prevent recurrence. There are no remaining open deliverables for this incident. Chunghwa Telecom will ensure continuous adherence to Web PKI standards.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 5•7 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2026-02-12.
Comment 6•7 months ago
|
||
Before this incident is closed, here are some observations.
It appears here that CHT failed to maintain a comprehensive and fully documented evaluation framework for third parties with access to CA facilities and systems, as required under WebTrust for CA V2.2.2 Criterion 3.1.11. The remediation actions implemented by CHT appear to be responsive. CHT improved alignment among procurement, access management, and compliance processes.
From a control-maturity perspective, this incident reflects a governance integration gap. While CHT maintained contracts and certain evaluation processes, its framework was not sufficiently institutionalized with vendor inventory records, access authorizations, and risk assessment documentation. As a result, it could not demonstrate that all third parties within its trust boundary were subject to clearly defined, risk-based evaluation standards.
This highlights an important infosec principle--that third parties with access to CA systems effectively extend a CA’s trust boundary. Oversight mechanisms must therefore be formalized, periodically validated, and integrated across organizational functions to eliminate control gaps. If procurement processes, access authorization records, and compliance review functions operate independently without a unified approach, then control gaps emerge even though underlying intent and some safeguards may exist.
Of note, this deficiency was identified along with Bug #2008782, Bug #2008799, and Bug #2008788, during the external audit process rather than through internal monitoring. In Comment#9 to Bug#2008788, CHT has acknowledged that this finding, like others from the 2025 audit cycle, was identified through the external audit process rather than through internal detection, and they have committed to strengthening proactive compliance validation mechanisms. Also of note, once the problem was identified, remediation was initiated promptly and completed within a defined timeframe. This pattern demonstrates responsiveness and execution capability, but also underscores the importance of maturing continuous compliance validation mechanisms so that governance-level integration gaps are detected internally before audit.
In summary:
- This incident illustrates the need to institutionalize third-party risk oversight as a formally integrated control framework, not merely as contract management or ad hoc evaluation.
- CHT needs to continually strengthen its internal compliance monitoring, cross-functional synchronization, and early identification of control gaps, which will be important to reduce reliance on periodic audits as the primary means of detecting governance-level deficiencies and to further mature CHT’s compliance oversight framework.
| Assignee | ||
Comment 7•7 months ago
|
||
Thank you for the detailed observations and for placing this incident in a broader compliance‑design context. We appreciate the clarity of the feedback and generally agree with the characterization provided.
In response, CHT has committed to strengthening continuous compliance assurance capabilities, including tighter coupling between procurement, access authorization, and compliance monitoring functions, and to establishing clearer ownership and accountability for third‑party trust‑boundary oversight. The objective is to ensure that governance‑level deficiencies are surfaced through internal controls and monitoring before they manifest as audit findings.
In summary, CHT remains committed to the ongoing maturation of our compliance governance to meet the expectations of the Web PKI ecosystem and will ensure continuous adherence to Web PKI standards.
Updated•7 months ago
|
Description
•