ANF AC: Finding #2 ETSI audit — information security policy not updated on the website
ANF AC reported a non-conformity found during its ETSI EN 319 401 annual conformity assessment audit: the Information Security Policy published on its website (OID 1.3.6.1.4.1.18332.101.80.1) was version 1.6, while the version provided during the audit was version 1.7. The discrepancy was attributed to a rollback of the website system during maintenance, which mistakenly restored an older version of the policy to the public website. The issue was detected by the external auditor during the ETSI audit and was described as a documentation/procedural non-compliance rather than an issuance or security problem; the report states that total number of certificates affected was 0 and issuance was not stopped. ANF AC stated that the updated policy continued to be used internally. In the thread, ANF AC reported that all action items were completed, including implementing post-rollback verification of critical website content, automating periodic comparison between internal and published policy, and conducting quarterly audits of the web repository with a compliance checklist. The bug is marked RESOLVED with resolution FIXED.
- ANF AC published Information Security Policy version 1.7 on its website repository.
- ANF AC’s website system maintenance performed a rollback that restored older published content.
- An external auditor identified the published policy version mismatch during the ETSI EN 319 401 annual conformity assessment audit.
- ANF AC restored Information Security Policy version 1.7 on its website.
- ANF AC submitted the incident report and described the non-conformity and remediation actions.
- ANF AC confirmed completion of the action items (verification, automation, and quarterly audits).
- Autoridad de Certificación (ANF AC) — Submitted an incident report describing that the website-published information security policy was version 1.6 instead of the internal/audited version 1.7, and explained the rollback cause and remediation plan.
- CCADB representative — Posted a final call for comments/questions on the incident report before it would be closed around 2025-07-08.
- Autoridad de Certificación (ANF AC) — Confirmed all action items were completed: post-rollback verification, automated internal-vs-published policy comparison, and quarterly web repository audits with a compliance checklist.