Chunghwa Telecom: Findings in 2025 WebTrust Audit (GTLSCA) — Missing/insufficient vulnerability scan coverage
This case is a self-disclosed incident report by Chunghwa Telecom regarding findings from a 2025 WebTrust audit for its GTLSCA operations. The incident was that vulnerability scans were not performed at the frequency required by WebTrust for CA - Network Security v1.7 Criterion 4.3 during the audit period: only one accepted vulnerability scan was performed in Q4 2024, while required quarterly scans for Q1–Q3 2025 were not completed as intended. Chunghwa Telecom stated that the CA Owner (MODA) delegated the remaining quarterly scans to a separate third-party cybersecurity service provider, but inadequate validation of the scanning methodology, scope, and frequency led to one required scan not being performed and to Q2/Q3 scans not fully covering intended systems, resulting in non-compliance identified during the annual audit. Chunghwa Telecom reported that after identification of the non-compliance, GTLSCA completed comprehensive vulnerability scans in accordance with WebTrust requirements, assessed and remediated results, and documented the outcomes. The CA also implemented monitoring mechanisms to track scheduled versus executed scans, validate asset coverage, detect scan failures/exceptions, and added automation and alerting to reduce reliance on manual processes. The bug was resolved as FIXED, with a report closure summary requesting closure after completion of the disclosed action items.
- Chunghwa Telecom initiated a new annual GTLSCA system maintenance and related services contract with the CA Owner (MODA).
- A vulnerability scan was performed for Q4 2024 under the 2024 contract.
- Vulnerability scans were not performed for Q1 2025, starting the non-compliance period.
- An auditing close meeting identified the non-compliance.
- Chunghwa Telecom completed comprehensive vulnerability scans and remediation to end the non-compliance period.
- The incident report was scheduled to be closed (final call for comments).
- Cht representative — Opened a preliminary incident report stating vulnerability scans were only performed in Q4 2024 during the audit period and citing WebTrust Criterion 4.3.
- Cht representative — Provided a full incident report describing delegation to third parties, inadequate validation leading to missed/incomplete quarterly scans, and a timeline of the non-compliance.
- Cht representative — Stated Chunghwa Telecom was monitoring the bug and had no new information.
- Cht representative — Updated action items, including performing and validating vulnerability scans, implementing scan execution monitoring, and increasing automation/alerting.
- Cht representative — Again stated Chunghwa Telecom was monitoring the bug and had no new information.
- Cht representative — Submitted the report closure summary, stating remediation actions were completed and requesting closure after action items were finished.
- CCADB representative — Issued a final call for comments or questions and noted the report would be closed around 2026-02-19.