Firmaprofesional: 2020 Audit Report Finding 2 out of 4 — contingency datacenter physical access controls
This case documents a non-conformity found in Firmaprofesional’s 2020 audit (Finding #2 out of 4) regarding physical security at the contingency (DR) datacenter. The audit observed that the contingency CPD rack is located in a housing room shared with other clients, with physical access to the rack protected by a key controlled by the CPD provider maintenance team, rather than Firmaprofesional having exclusive, auditable control. Firmaprofesional stated that it registered the non-conformity in its JIRA on 2020-04-14 and established an action plan. Firmaprofesional reported that, in response, it requested its contingency CPD supplier (ADAM) to install an intelligent rack access lock enabling dual control, and it also stated that additional measures were added to improve physical security regarding access to the rack where contingency teams are located. In the thread, Mozilla asked about whether two people from Firmaprofesional are required to access the DR datacenter, and Firmaprofesional clarified that two people are required (at least one manager and one technical staff). Mozilla indicated the matter could be closed on or about 6-November-2020, and the bug is marked RESOLVED with resolution FIXED.
- Firmaprofesional’s eIDAS audit observed the contingency CPD rack’s physical access arrangement in a shared housing room.
- Firmaprofesional registered the non-conformity in its JIRA and established an action plan.
- Firmaprofesional requested ADAM to install an intelligent rack access lock with dual control.
- Mozilla indicated the matter could be closed on or about 6-November-2020.
- Autoridad de Certificacion Firmaprofesional — Firmaprofesional described Finding #2: the contingency datacenter rack is in a shared housing room and access is controlled by the CPD provider maintenance team, and stated it would fix the issue.
- Community commenter — Ryan Sleevi asked for more detail because there were no updates and questioned whether the DR physical security controls and HSM initialization meaning posed a critical risk.
- Autoridad de Certificacion Firmaprofesional — Firmaprofesional explained that the DR site is passive and requires several people to load keys into HSMs following procedures, and said additional physical security measures were added for rack access.
- Community commenter — Ryan asked for clarification on why DR security controls were distinct from what Mozilla expects under BRs and NCSSRs.
- Isigma representative — Firmaprofesional (via chemalogo) stated the non-conformity was about controls not being the same level as the main datacenter and reiterated the DR activation process and efforts to add measures.
- Mozilla representative — Ben Wilson asked whether at least two people from Firmaprofesional are required to access the DR datacenter and whether there are plans to make DR rack access two-person.
- Isigma representative — Firmaprofesional confirmed that two people from Firmaprofesional are required to access the DR datacenter (at least one manager and one technical staff).
- Mozilla representative — Ben Wilson stated he believed the matter could be closed on or about 6-November-2020 unless additional issues or concerns arose.