SwissSign: recommendation on CA-specific risk assessment
This case is based on an ETSI audit report that included a recommendation for SwissSign to improve its CA-specific risk assessment process. SwissSign disclosed the audit recommendation in this Bugzilla, stating that its existing risk assessments were primarily asset-based and did not explicitly consider process- and operations-based risks in an end-to-end view of CA-related activities. SwissSign reported that certificate issuance was not halted because the recommendation did not impact issuance. As remediation, SwissSign performed a comprehensive process and operations risk assessment for CA-related processes, and documented the identified risks, mitigations, and acceptance criteria, integrating them into its risk management framework. SwissSign stated that all action items associated with the recommendation were completed and that it will continue monitoring the Bugzilla for community feedback. The bug was resolved as FIXED, and CCADB noted it would be closed on approximately 2026-05-07 if no further comments were received.
- An ETSI audit report was published containing a recommendation to enhance SwissSign’s CA-specific risk assessment approach.
- SwissSign submitted a full incident report describing the audit recommendation and planned remediation action item.
- SwissSign reported completion of the action item to perform process/operations risk assessment and requested report closure.
- The incident report was scheduled to be closed if no further comments were received.
- SwissSign AG — SwissSign opened the bug with a preliminary incident report stating the audit recommended improving its risk assessment process to better assess CA-related operational risks.
- SwissSign AG — SwissSign provided a full incident report (CA/B-F TLS BR, 5) explaining the recommendation, stating issuance was not halted, and adding an action item to perform process/operations risk assessment by 2026-04-30 (in progress).
- SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
- SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
- SwissSign AG — SwissSign reported the action item was completed (status: done) and described remediation integrating process/operations-based risk assessments into its risk management framework, continuing to monitor for community feedback.
- CCADB representative — CCADB posted a final call for comments and stated the incident report would be closed on approximately 2026-05-07.