← Autoridad de Certificación (ANF AC) cases
Bugzilla #1970565 Policy Compliance

ANF AC: Finding #2 ETSI Audit - Information security policy not updated on the website

RESOLVED FIXED Autoridad de Certificación (ANF AC)
AI Summary

During an ETSI EN 319 401 audit, it was found that the Information Security Policy published on the ANF AC website was outdated. The publicly available version was 1.6, while the latest approved version was 1.7. This discrepancy was due to a rollback during website maintenance that restored an older version of the policy. The issue was identified by an external auditor, but it did not impact certificate issuance or security. ANF AC has since implemented measures to prevent recurrence, including post-rollback verification and automated checks.

Model: gpt-4o-mini Generated: 2026-06-13 15:22 UTC Confidence: 0.90
Chronology
  1. Publication of version 1.7 of the Information Security Policy
  2. Rollback of the company’s website system
  3. Non-compliance identified by an external auditor
  4. Restoration of version 1.7 of the Information Security Policy on the website
Participants
Yulier Nuñez
External References
Similar Local Cases
#1974325 RESOLVED Policy Compliance Opened 2025-06-26 · Closed 2025-07-16 · 57% similar
ANF AC: Test Certificates Non-Compliance
#1970567 RESOLVED Policy Compliance Opened 2025-06-05 · Closed 2025-07-08 · 57% similar
ANF AC: Finding #4 ETSI Audit - Missing one Revocation circumstance on CPS
#1970559 RESOLVED Policy Compliance Opened 2025-06-05 · Closed 2025-07-08 · 49% similar
ANF AC: Finding #3 ETSI Audit - Improve documental explanation revocation request >24h on CPS
#1969842 RESOLVED Policy Compliance Opened 2025-06-02 · Closed 2025-07-16 · 49% similar
ANF AC: Finding #1 ETSI Audit - Missing log retention period in Terms and Conditions v1.9
#1969839 RESOLVED Policy Compliance Opened 2025-06-02 · Closed 2025-06-04 · 47% similar
ANF: Missing log retention period in Terms and Conditions v1.9
#1530971 RESOLVED Policy Compliance Opened 2019-02-27 · Closed 2023-02-22 · 41% similar
HARICA: P-384,ecdsa-with-SHA256 Certificates
#1542082 RESOLVED Policy Compliance Opened 2019-04-04 · Closed 2023-02-22 · 39% similar
IdenTrust: Failure to disclose Unconstrained intermediate Within 7 Days
#1865235 RESOLVED Policy Compliance Opened 2023-11-17 · Closed 2023-12-07 · 39% similar
DigiCert: Late background refreshment check

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action