Firmaprofesional: 2019 audit finding #2 (6.4) — facility, management, and operational controls (auditor access to audit logs)
This case concerns a 2019 audit finding for Firmaprofesional related to facility, management, and operational controls (6.4), specifically that full read/write access to audit logs was restricted to authorized individuals while the assigned auditor role did not have permissions to review the logs (read-only access was expected). Firmaprofesional stated it was already aware of the issue before the March 2019 eIDAS audit, and that the issue did not affect certificate issuance. In response, Firmaprofesional registered the non-conformity in its JIRA in May 2019 and established an action plan, including an obligation to establish a revocation process. The company escalated the issue to its steering committee in July 2019, which decided to pursue a project to collect logs from tools involved in the certificate lifecycle management into a single point of revision, with the possibility of defining an auditor role, planned within the 2020 budget. In December 2019, it created the auditor role in the main tool involved in certificate management (EJBCA EE), and in January 2020 the audit role was created and delivered to the personnel involved. Firmaprofesional later clarified that it was already finalizing deployment of a cloud-based centralized log management system (Elastic Stack) to centralize and correlate logs for the whole certificate lifecycle management system. A Fastly participant stated that remediation was complete, and the bug is marked RESOLVED with resolution FIXED.
- Firmaprofesional registered the audit non-conformity in its JIRA and established an action plan.
- Firmaprofesional escalated the issue to its steering committee to plan centralized log collection and an auditor role.
- Firmaprofesional created an auditor role in EJBCA EE as an interim step.
- The auditor role was created on EJBCA and delivered to the personnel involved.
- A participant indicated remediation was complete.
- Isigma representative — Described the audit finding about auditor access to audit logs, stated it did not affect certificate issuance, and provided a timeline of remediation actions including JIRA tracking, steering committee decisions, and creation of an auditor role in EJBCA EE.
- Community commenter — Asked for confirmation of the before/after state, including that EJBCA now provides the auditor account read-only access to logs without system administrator assistance.
- Isigma representative — Clarified that Firmaprofesional was already executing deployment of a centralized log management system (Elastic Stack) for all logs supporting certificate lifecycle management.
- Community commenter — Commented on cloud scope considerations and noted progress.
- Fastly representative — Stated that all questions had been answered and remediation was complete.