← SwissSign AG cases
Bugzilla #1990284
CCADB Compliance
SwissSign: recommendation on review of key pair generation implementation
RESOLVED
FIXED
SwissSign AG
AI Summary
The audit report for SwissSign recommended improvements in the regular review of its key pair generation implementation in accordance with NIST SP 800-89. Although the audit did not identify any non-compliance, it highlighted the need for a documented monitoring process for updates to the specification. SwissSign has since established this monitoring process and confirmed its commitment to ongoing compliance with relevant standards. The case is now resolved with all action items completed.
Chronology
- Preliminary incident report submitted.
- Full incident report submitted.
- Monitoring process for NIST SP 800-89 changes completed.
- Final call for comments before closure.
Participants
Sandy Balzer
External References
Similar Local Cases
SwissSign: recommendation on log review process
SwissSign: recommendation on BIA/BCP test coverage
SwissSign: recommendation on firewall review
SwissSign: recommendation on publication process for CA related data
SwissSign: recommendation on linting software updates
SwissSign: Audit Letter Validation failures on intermediate certificates
IdenTrust: Delay in updating a Bug 2016585 - Next update
Microsoft PKI Services: Incomplete Logical Access Review Audit Evidence