← Chunghwa Telecom cases
Bugzilla #2008782
Audit Related
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #1 - mass certificate revocation plan
RESOLVED
FIXED
Chunghwa Telecom
AI Summary
Chunghwa Telecom's GTLSCA faced issues during a 2025 WebTrust audit regarding its mass certificate revocation plan, which was not fully compliant with CAB requirements. The plan lacked necessary approvals and documentation, impacting its readiness for timely mass revocation in case of incidents. The non-compliance was not due to a security breach but rather procedural gaps. Chunghwa Telecom has since updated its procedures and completed necessary drills to ensure compliance, and all action items have been addressed.
Chronology
- Non-compliance start date
- Non-compliance identified date
- Non-compliance end date
- Audit Readiness Alignment Checklist completed
- Document Governance Improvements completed
- Incident report closure
Participants
Tsung-Min Kuo
External References
Similar Local Cases
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
Chunghwa Telecom Audit Statements
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #5 – CMDB
Buypass: Findings in 2025 ETSI Audit - Audit Incident Report #1 - Compliance auditing on support processes
Telekom Security: Failure to file a bug for two findings from the 2024 Audit
certSIGN: Findings in 2025 ETSI Audit - Audit Incident Report #1 – Improve clarity in CPS