Sectigo: Trusted Role Access provided prior to completion of onboarding process
Sectigo reported a compliance incident discovered during its annual WebTrust audit. The auditors found that access to Certificate Systems was granted to two employees before completion of criminal background checks, and to three additional employees before completion of formal validation training evidence. Sectigo stated that its CPS requires background checks before access is granted, and that while identity verification was completed, criminal background checks were completed after access was provided. For validation training, Sectigo said buddy-system training was completed for the employees but it only had “eye-witness accounts” as evidence, and the formal Validation Training Exam Course was completed after access was granted. Sectigo reported the issue to the Mozilla community to allow tracking of the errors and noted that its audit firm intended to call out these errors as findings in the upcoming WebTrust report. The incident handling action item was completed, and Mozilla indicated it would close the bug unless questions or issues remained. The bug is resolved as FIXED.
- Certificate System accounts were created for Employee #1 and Employee #2 before criminal background checks were completed.
- A Certificate System account was created for Employee #3 in a validation capacity before formal validation training evidence was completed.
- Certificate System accounts were created for Employee #4 and Employee #5 in a validation capacity before formal validation training evidence was completed.
- Sectigo submitted the incident report describing the onboarding/access timing issues found during its annual WebTrust audit.
- Sectigo completed the final action item for incident handling.
- Sectigo — Sectigo provided a preliminary incident report stating auditors found access granted before completion of background checks and validation training.
- Sectigo — Sectigo posted the full incident report, including CPS/EVG language discussion, impact, and a timeline of when access and checks/training occurred.
- Sectigo — Sectigo stated the final action item in the incident report was completed and asked to continue monitoring for questions.
- Sectigo — Tim Callan asked whether the bug could be closed.
- Mozilla representative — Mozilla stated it would close the bug on 10-Jul-2024 unless issues or questions remained.