← SwissSign AG cases
Bugzilla #1990254 Ca Documents Audit Finding

SwissSign: recommendation on risk assessment

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case documents an ETSI audit report for SwissSign that included a recommendation to improve SwissSign’s risk assessment processes and the structured tracking of countermeasures in alignment with ETSI EN 319 401 §5-04 (REQ 5-04). SwissSign stated that certificate issuance was not affected at any time because the audit recommendation was not a certificate-issuance impact. SwissSign opened the bug as an audit-disclosed incident report and provided a root cause analysis describing a gap between performing risk assessments and having documentation and structured countermeasure tracking that fully match current best practices. An action item was set to update the risk assessment process to match ETSI EN 319 401 §5-04, with a due date initially listed as 2026-04-30. On 2026-04-27, SwissSign reported that the action item was completed, reviewed by its auditors, and that the remediation included improved documentation standards and a structured approach for tracking identified risks and associated countermeasures. The incident report was then subject to a final call for comments and was scheduled to be closed on approximately 2026-05-04; the bug status is RESOLVED with resolution FIXED.

Model: gpt-5.4-nano Generated: 2026-06-13 20:48 UTC Revised: 2026-06-16 18:22 UTC Confidence: 0.86 8 comments
Chronology
  1. An ETSI audit report containing a recommendation on SwissSign’s risk assessment and countermeasure tracking was published.
  2. SwissSign opened the Bugzilla incident report based on the ETSI audit recommendation.
  3. SwissSign completed the remediation to align its risk assessment process and countermeasure tracking with ETSI EN 319 401 §5-04 and reported closure readiness.
  4. The bug was expected to be closed after the final call for comments.
Thread Activity
  1. SwissSign AG — SwissSign submitted a preliminary incident report stating the ETSI audit recommended improving risk assessment processes and tracking of countermeasures, referencing ETSI EN319 401 and REQ 5-04.
  2. SwissSign AG — SwissSign provided the full incident report, stating certificate issuance was not impacted and describing the root cause as documentation and structured tracking not fully matching ETSI EN 319 401 §5-04.
  3. SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
  4. SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
  5. Internet Security Research Group — Jacob requested that the Next Update field for this and other SwissSign incident reports be set to the Due Date to reduce weekly update burden.
  6. CCADB representative — CCADB staff agreed it was reasonable and noted an issue was recorded to encourage CA Owners to make nextUpdate recommendations going forward.
  7. SwissSign AG — SwissSign reported completion of the action item, auditor review, and remediation details, and stated it would continue monitoring the Bugzilla for community feedback.
  8. CCADB representative — CCADB staff issued a final call for comments and stated the incident report would be closed on approximately 2026-05-04.
Participants
SwissSign AG Internet Security Research Group CCADB representative
Similar Local Cases
#1990272 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on backup testing
#1990274 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on synchronization of staging and production environments
#1990275 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on publication process for CA related data
#1990276 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-07 · 100% similar
SwissSign: recommendation on evaluation of cloud service providers
#1990277 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 83% similar
SwissSign: recommendation on CA-specific risk assessment
#1990284 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-04 · 79% similar
SwissSign: recommendation on review of key pair generation implementation
#1359533 RESOLVED Ca Documents Opened 2017-04-25 · Closed 2022-12-08 · 79% similar
SwissSign Audit info
#1614450 RESOLVED Audit Finding Opened 2020-02-10 · Closed 2022-11-14 · 79% similar
SwissSign: Audit Letter Validation failures on intermediate certificates

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action