← SwissSign AG cases
Bugzilla #1990277 Audit Finding Self Reported Incident

SwissSign: recommendation on CA-specific risk assessment

RESOLVED FIXED SwissSign AG
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is based on an ETSI audit report that included a recommendation for SwissSign to improve its CA-specific risk assessment process. SwissSign disclosed the audit recommendation in this Bugzilla, stating that its existing risk assessments were primarily asset-based and did not explicitly consider process- and operations-based risks in an end-to-end view of CA-related activities. SwissSign reported that certificate issuance was not halted because the recommendation did not impact issuance. As remediation, SwissSign performed a comprehensive process and operations risk assessment for CA-related processes, and documented the identified risks, mitigations, and acceptance criteria, integrating them into its risk management framework. SwissSign stated that all action items associated with the recommendation were completed and that it will continue monitoring the Bugzilla for community feedback. The bug was resolved as FIXED, and CCADB noted it would be closed on approximately 2026-05-07 if no further comments were received.

Model: gpt-5.4-nano Generated: 2026-06-13 20:48 UTC Revised: 2026-06-16 18:23 UTC Confidence: 0.86 6 comments
Chronology
  1. An ETSI audit report was published containing a recommendation to enhance SwissSign’s CA-specific risk assessment approach.
  2. SwissSign submitted a full incident report describing the audit recommendation and planned remediation action item.
  3. SwissSign reported completion of the action item to perform process/operations risk assessment and requested report closure.
  4. The incident report was scheduled to be closed if no further comments were received.
Thread Activity
  1. SwissSign AG — SwissSign opened the bug with a preliminary incident report stating the audit recommended improving its risk assessment process to better assess CA-related operational risks.
  2. SwissSign AG — SwissSign provided a full incident report (CA/B-F TLS BR, 5) explaining the recommendation, stating issuance was not halted, and adding an action item to perform process/operations risk assessment by 2026-04-30 (in progress).
  3. SwissSign AG — SwissSign said it was monitoring the Bugzilla for community feedback.
  4. SwissSign AG — SwissSign again stated it was monitoring the Bugzilla for community feedback.
  5. SwissSign AG — SwissSign reported the action item was completed (status: done) and described remediation integrating process/operations-based risk assessments into its risk management framework, continuing to monitor for community feedback.
  6. CCADB representative — CCADB posted a final call for comments and stated the incident report would be closed on approximately 2026-05-07.
Participants
SwissSign AG CCADB representative
External References
Similar Local Cases
#1990282 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-11 · 100% similar
SwissSign: recommendation on linting software updates
#1990284 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-04 · 100% similar
SwissSign: recommendation on review of key pair generation implementation
#1990281 RESOLVED Audit Finding Self Reported Incident Opened 2025-09-23 · Closed 2026-05-07 · 94% similar
SwissSign: recommendation on self-assessment tool
#1965828 RESOLVED Self Reported Incident Security Incident Opened 2025-05-12 · Closed 2025-08-19 · 88% similar
SwissSign: OCSP outage
#2033000 RESOLVED Ca Certificate Compliance Incident Self Reported Incident Policy Document Issue Opened 2026-04-17 · Closed 2026-07-09 · 87% similar
SwissSign: Certificate Profile error for S/MIME MV
#1990254 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 83% similar
SwissSign: recommendation on risk assessment
#1990275 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 83% similar
SwissSign: recommendation on publication process for CA related data
#1990272 RESOLVED Ca Documents Audit Finding Opened 2025-09-23 · Closed 2026-05-04 · 82% similar
SwissSign: recommendation on backup testing

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action