← SwissSign AG cases
Bugzilla #1921424
Audit Related
SwissSign: Findings in 2024 Audit
RESOLVED
FIXED
SwissSign AG
AI Summary
SwissSign AG submitted an initial audit incident report detailing findings from their 2024 audit. Key findings include the need for improved access control for PEM device tokens, employee training on mis-issuance procedures, and enhanced media handling protocols. The audit identified several areas for improvement, including dual control processes and monitoring of SHA-1 signed certificate requests. SwissSign has committed to addressing these findings and has provided a timeline for corrective actions. The case is now resolved, with all non-conformities addressed.
Chronology
- Initial audit incident report submitted.
- Post audit incident report published.
- Request to close Bugzilla case.
- Bugzilla case closed.
Participants
Sandy Balzer
B Wilson
External References
Similar Local Cases
SwissSign: recommendation on BIA/BCP review
SwissSign: recommendation on document release dual control
SwissSign: recommendation on CA-specific risk assessment
SwissSign Audit info
Firmaprofesional: 2021 Audit Report Finding 1 out of 3
Firmaprofesional: 2020 Audit Report Finding 3 out of 4
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report
Telia: Findings in 2024 Audit