← Autoridad de Certificación (ANF AC) cases
Bugzilla #1970565 Audit Finding Self Reported Incident

ANF AC: Finding #2 ETSI audit — information security policy not updated on the website

RESOLVED FIXED Autoridad de Certificación (ANF AC)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

ANF AC reported a non-conformity found during its ETSI EN 319 401 annual conformity assessment audit: the Information Security Policy published on its website (OID 1.3.6.1.4.1.18332.101.80.1) was version 1.6, while the version provided during the audit was version 1.7. The discrepancy was attributed to a rollback of the website system during maintenance, which mistakenly restored an older version of the policy to the public website. The issue was detected by the external auditor during the ETSI audit and was described as a documentation/procedural non-compliance rather than an issuance or security problem; the report states that total number of certificates affected was 0 and issuance was not stopped. ANF AC stated that the updated policy continued to be used internally. In the thread, ANF AC reported that all action items were completed, including implementing post-rollback verification of critical website content, automating periodic comparison between internal and published policy, and conducting quarterly audits of the web repository with a compliance checklist. The bug is marked RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 15:22 UTC Revised: 2026-06-16 18:03 UTC Confidence: 0.86 3 comments
Chronology
  1. ANF AC published Information Security Policy version 1.7 on its website repository.
  2. ANF AC’s website system maintenance performed a rollback that restored older published content.
  3. An external auditor identified the published policy version mismatch during the ETSI EN 319 401 annual conformity assessment audit.
  4. ANF AC restored Information Security Policy version 1.7 on its website.
  5. ANF AC submitted the incident report and described the non-conformity and remediation actions.
  6. ANF AC confirmed completion of the action items (verification, automation, and quarterly audits).
Thread Activity
  1. Autoridad de Certificación (ANF AC) — Submitted an incident report describing that the website-published information security policy was version 1.6 instead of the internal/audited version 1.7, and explained the rollback cause and remediation plan.
  2. CCADB representative — Posted a final call for comments/questions on the incident report before it would be closed around 2025-07-08.
  3. Autoridad de Certificación (ANF AC) — Confirmed all action items were completed: post-rollback verification, automated internal-vs-published policy comparison, and quarterly web repository audits with a compliance checklist.
Participants
Autoridad de Certificación (ANF AC) CCADB representative
External References
Similar Local Cases
#1973236 RESOLVED Incident Policy Document Issue Self Reported Incident Opened 2025-06-20 · Closed 2025-07-09 · 87% similar
ANF AC: Delayed Disclosure of Updated Policy Documents in CCADB
#1974325 RESOLVED Incident Self Reported Incident Opened 2025-06-26 · Closed 2025-07-16 · 87% similar
ANF AC: Test Certificates Non-Compliance
#2008803 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-12 · 80% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
#2009045 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-07 · Closed 2026-02-19 · 80% similar
Chunghwa Telecom: Delayed disclosure to Bug 2008788 GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#1990284 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-04 · 78% similar
SwissSign: recommendation on review of key pair generation implementation
#2008788 RESOLVED Self Reported Incident Audit Finding Opened 2026-01-06 · Closed 2026-02-11 · 78% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2050383 ASSIGNED Self Reported Incident Repository Issue Problem Reporting Failure Opened 2026-06-25 Still Open · 77% similar
ANF AC: Incident Report - OCSP "unknown" response for CT precertificate
#1990277 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 77% similar
SwissSign: recommendation on CA-specific risk assessment

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action