Firmaprofesional: 2021 Audit Report Finding 1 out of 3
This case documents a finding identified in Firmaprofesional’s annual eIDAS audit carried out in March 2021 (29th). The finding states that the existence of a user exercising a trusted role (System Administrator) was evidenced without proof of the formal assignment and acceptance of that role. Firmaprofesional said the issue was registered in its JIRA on 2021-04-08 and that an action plan was established after studying the ETSI obligations. As remediation, Firmaprofesional modified the process “PR101-Human Resources” on 2021-04-08 to require each manager to validate the correct assignment and acceptance of the role before it becomes effective and permissions/credentials are delivered. Firmaprofesional stated that the new process was validated by its Human Resources Director on 2021-04-28 and that new personnel incorporations already follow the requirement. The bug was resolved as FIXED, and Mozilla participant guidance in the thread focused on the incident reporting expectations and the need for more substantive incident reporting, including how the process allowed the issue to be missed until the auditor detected it. Firmaprofesional responded that the Security Officer is the only person who can grant such a role and described procedural changes intended to prevent recurrence by improving communication between departments (HR and the technical/security side).
- Firmaprofesional’s annual eIDAS audit identified a finding about missing evidence of formal assignment and acceptance for a trusted System Administrator role.
- Firmaprofesional registered the finding in JIRA and established an action plan, then modified its PR101-Human Resources process to require validation of role assignment and acceptance.
- Firmaprofesional validated the updated HR process with its Human Resources Director.
- The CA Program bug was created to report the audit finding (resolved later as FIXED).
- Autoridad de Certificacion Firmaprofesional — Submitted the incident report describing the eIDAS audit finding and Firmaprofesional’s remediation steps, including the PR101-Human Resources process change and validation date.
- Community commenter — Commented that this was the third consecutive year of audit findings and asked for more substance, including why it was not reported timely and what the full issue was.
- Autoridad de Certificacion Firmaprofesional — Responded to the request for more substance, stating the Security Officer is the only person who can grant the role and describing how notification timing and evidence were handled.
- Community commenter — Further emphasized that future suspected incidents should be disclosed transparently and asked how the process went wrong to allow the issue to be missed until the auditor detected it.
- Autoridad de Certificacion Firmaprofesional — Provided additional explanation of how logs/records are managed and described a redesigned procedure to improve communication between HR and the security/technical side to prevent recurrence.
- Mozilla representative — Stated there were no further suggestions and that the bug would be scheduled to close on or about 13-Aug-2021.