Microsoft PKI Services: Incomplete Logical Access Review Audit Evidence
This case is a self-disclosure by Microsoft PKI Services (DSRE PKI at Microsoft) regarding incomplete audit evidence for logical access reviews. During a preliminary audit in January, Microsoft was asked to provide documentation proving that human reviews of logical access were performed; while other logical access logs were being collected and reviewed, evidence proving that a review artifact had been created was not completed. By the conclusion of the audit period in June, Microsoft confirmed the need for a proof-of-review artifact and stated that a public disclosure is required. Microsoft reported that there were no non-compliant certificates issued. In response, Microsoft updated its documented process within one day of realizing the documentation gap to increase review frequency and clarify language, and it developed automation to monitor for creation of a new evidence file and alert if review evidence was not created within a time window. Microsoft later stated that the monitoring and alerting were fully implemented and validated, and Mozilla indicated the bug would be closed on 21-Sept-2020 unless additional issues arose. The bug is marked RESOLVED with resolution FIXED.
- Audit period began (1 July 2019 to 30 June 2020) for logical access review evidence.
- BDO identified evidence changes and a delay between expected logical access review dates.
- Microsoft updated its documented process to clarify task cadence and requirements.
- Annual audit concluded with evidence review and discussion confirming the need for a proof-of-review artifact.
- Microsoft reported automated monitoring and alerting changes were code-complete and deployed to production.
- Microsoft stated final monitoring and alerting changes were planned to be completed by 30 September 2020.
- Microsoft reported monitoring and alerting were fully implemented and validated.
- Disabled representative — Filed the self-disclosure describing incomplete logical access review audit evidence, stating no non-compliant certificates were issued, and outlining process updates and planned automation by 30-Sep-2020.
- Community commenter — Set the next update to a midpoint of the proposed monitoring/alerting timeline to ensure progress toward 2020-09-30.
- Disabled representative — Reported automation logic was code-complete, deployed to production, and planned final monitoring/alerting changes by 15-Sep-2020 with completion by 30-Sep-2020.
- Mozilla representative — Set the next update to 15-Sept-2020.
- Disabled representative — Reported that monitoring and alerting were fully implemented and validated.
- Mozilla representative — Indicated the bug would be scheduled for closure on 21-Sept-2020 unless additional issues were discussed.
- Community commenter — Updated the description to reflect one organization (Microsoft) rather than internal work divisions.