Microsoft PKI Services: Vulnerability Management Exception Tracking
This case is a self-disclosure by Microsoft PKI Services about deficiencies found during an audit period in its Vulnerability Management process. The auditors issued a qualified opinion stating that, upon discovery of a Critical Vulnerability, certain required actions did not occur within 96 hours, which caused WebTrust Principles and Criteria for Certification Authorities – Network Security – Version 1.0 to not be met. Microsoft reported that when exceptions to the 96-hour remediation timeline occurred, the vulnerability mitigation plan and timelines were known internally but were not consistently documented and attached to the vulnerability tracker, and the vulnerability dashboard did not display the remediation plan for exceptions. Microsoft stated that no certificates were impacted by this process issue. Microsoft opened and updated this bug with a root cause analysis and action items to document mitigation plans for 96-hour exceptions and to expand the vulnerability tracking dashboard to include additional fields, including the mitigation plan. Microsoft later reported completing both action items and asked whether the bug could be closed; Mozilla indicated it would close the bug on 9-Aug-2024 unless further discussion was needed. The bug is marked RESOLVED with resolution FIXED.
- Audit period ended; auditors issued a qualified opinion identifying deficiencies in Microsoft PKI Services vulnerability mitigation documentation and timelines.
- Auditor provided draft audit reports containing the qualified opinion.
- Microsoft PKI Services opened the Bugzilla case in response to the audit finding.
- Microsoft reported completion of documenting mitigation plans for 96-hour exceptions and set a due date for dashboard expansion.
- Microsoft reported completion of the remaining dashboard action item and requested closure.
- Bug status was updated to RESOLVED (FIXED).
- Disabled representative — Microsoft submitted an incident report describing the qualified audit finding, the impact on producing evidence for documented mitigation plans during >96-hour exceptions, and action items to document mitigation plans and update the vulnerability tracking dashboard.
- Disabled representative — Microsoft posted an updated incident report with the same qualified-opinion language and reiterated the root cause and action items.
- Disabled representative — Microsoft reported it completed the action item to document mitigation plans for 96-hour exceptions and provided a due date for expanding the dashboard.
- Disabled representative — Microsoft stated it completed the final action item (dashboard expansion) and asked if the bug could be closed.
- Mozilla representative — Mozilla responded that it would close the bug on Friday, 9-Aug-2024, unless discussions were needed.