← Microsoft Corporation cases
Bugzilla #1906028 CCADB Compliance

Microsoft PKI Services: Vulnerability Management Exception Tracking

RESOLVED FIXED Microsoft Corporation
AI Summary

The Microsoft PKI Services team faced challenges in documenting vulnerability mitigation plans and timelines during an audit period. A qualified opinion from auditors highlighted deficiencies in their process, particularly regarding the 96-hour remediation timeline for critical vulnerabilities. The team acknowledged the need for improved documentation and tooling to track exceptions effectively. They have since completed the action item to document mitigation plans and expanded their vulnerability tracking dashboard to enhance compliance. The case is now resolved.

Model: gpt-4o-mini Generated: 2026-06-13 21:18 UTC Confidence: 0.90
Chronology
  1. Auditor provided draft audit reports with qualified opinion.
  2. Bugzilla case opened.
  3. Final action item completed.
Participants
u654666@disabled.tld bwilson@mozilla.com
External References
Similar Local Cases
#1652827 RESOLVED CCADB Compliance Opened 2020-07-14 · Closed 2024-06-30 · 68% similar
Microsoft PKI Services: Incomplete Logical Access Review Audit Evidence
#2026453 RESOLVED CCADB Compliance Opened 2026-03-26 · Closed 2026-04-22 · 48% similar
Microsoft PKI Services: Failure to report Bugzilla 2026452 within 72 hrs
#2021175 RESOLVED CCADB Compliance Opened 2026-03-05 · Closed 2026-04-03 · 48% similar
Microsoft PKI Services: Failure to update action item status within 3 days
#1588213 RESOLVED CCADB Compliance Opened 2019-10-11 · Closed 2024-06-30 · 47% similar
IdenTrust: Missing Thumbprints for Intermediate CA certificates In Some Annual Audit Reports
#1931413 RESOLVED CCADB Compliance Opened 2024-11-14 · Closed 2024-12-27 · 46% similar
Google Trust Services: New hire onboarding deviation from written procedure
#1784820 RESOLVED CCADB Compliance Opened 2022-08-15 · Closed 2023-08-16 · 46% similar
CFCA: Delayed reporting of intermediate CA certificate
#2013375 RESOLVED CCADB Compliance Opened 2026-01-29 · Closed 2026-02-18 · 45% similar
DigiCert: Issues with CCADB entries
#1906115 RESOLVED CCADB Compliance Opened 2024-07-03 · Closed 2024-08-28 · 45% similar
Netlock: Delayed reply from CPR sent to contact listed in section 1.5.2 of CP/S

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action