← Certigna cases
Bugzilla #1973032 Audit Related

Certigna: Finding #2 ETSI Audit - Risks regarding the certification of device not described

RESOLVED FIXED Certigna
AI Summary

The ETSI audit for Certigna identified that the business risks associated with the potential loss of certification for a cryptographic device were inadequately described in their risk assessment. Although the risks are managed, the lack of detail hindered the evaluation of their real business impact. Certigna has since updated their risk management procedures and enriched their risk assessment to include more comprehensive descriptions of these risks. All action items related to this incident have been completed, and the case is now resolved.

Model: gpt-4o-mini Generated: 2026-06-13 21:30 UTC Confidence: 1.00
Chronology
  1. Annual update of risk assessment.
  2. Auditor identifies lack of description of business risks.
  3. Risk management procedure updated.
  4. Validation of deviation resolution by auditor.
Participants
Josselin Allemandou R. Delval
External References
Similar Local Cases
#1907833 RESOLVED Audit Related Opened 2024-07-15 · Closed 2024-08-28 · 57% similar
Certigna: Findings in 2024 ETSI Audit – Audit Incident Report
#1339126 RESOLVED Audit Related Opened 2017-02-13 · Closed 2022-12-08 · 47% similar
Audit info for Certigna
#1990277 RESOLVED Audit Related Opened 2025-09-23 · Closed 2026-05-07 · 43% similar
SwissSign: recommendation on CA-specific risk assessment
#1983265 RESOLVED Audit Related Opened 2025-08-15 · Closed 2025-11-20 · 43% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #5 – CMDB
#1965806 RESOLVED Audit Related Opened 2025-05-12 · Closed 2025-06-12 · 42% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #3 – Missing certSIGN OID on Terms and Conditions
#2008029 RESOLVED Audit Related Opened 2025-12-30 · Closed 2026-02-09 · 42% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #8 – Human Resources Management
#1965805 RESOLVED Audit Related Opened 2025-05-12 · Closed 2025-06-12 · 41% similar
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #2 – Add test certificates in CPS
#1976860 RESOLVED Audit Related Opened 2025-07-11 · Closed 2025-08-21 · 41% similar
Telekom Security: Failure to file a bug for two findings from the 2024 Audit

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action