← Chunghwa Telecom cases
Bugzilla #2008803 Audit Related

Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #4 - Missing evaluation for third parties

RESOLVED FIXED Chunghwa Telecom
AI Summary

During the 2025 WebTrust audit, Chunghwa Telecom (GTLSCA) was found to lack objective evidence of adequate audit and evaluation for third-party vendors with access to CA facilities. The non-compliance period was identified from October 2024 to December 2025, during which GTLSCA failed to maintain a comprehensive evaluation framework. Although no certificates were misissued, the incident highlighted significant gaps in third-party risk management and compliance processes. Remediation actions have been implemented to enhance oversight and ensure adherence to Web PKI standards.

Model: gpt-4o-mini Generated: 2026-06-13 21:36 UTC Confidence: 0.90
Chronology
  1. Initiate new annual cycle of system maintenance and procurement projects.
  2. Non-compliance identified during GTLSCA Auditing Close Meeting.
  3. Complete comprehensive risk assessment of third-party vendors.
  4. Revise internal control assessment process.
  5. Incident report closure.
Participants
Tsung-Min Kuo
Similar Local Cases
#2008799 RESOLVED Audit Related Opened 2026-01-06 · Closed 2026-02-19 · 64% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #3 - Missing vulnerability scan
#2008788 RESOLVED Audit Related Opened 2026-01-06 · Closed 2026-02-11 · 62% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #2 - Domain validation records without the TLS BR version
#2008782 RESOLVED Audit Related Opened 2026-01-06 · Closed 2026-02-18 · 59% similar
Chunghwa Telecom: Findings in 2025 WebTrust Audit - GTLSCA Audit Incident Report #1 - mass certificate revocation plan
#1483068 RESOLVED Audit Related Opened 2018-08-13 · Closed 2022-12-08 · 47% similar
Chunghwa Telecom Audit Statements
#2008026 RESOLVED Audit Related Opened 2025-12-30 · Closed 2026-02-09 · 41% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #5 – Risk Management
#2008029 RESOLVED Audit Related Opened 2025-12-30 · Closed 2026-02-09 · 41% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #8 – Human Resources Management
#1865880 RESOLVED Audit Related Opened 2023-11-21 · Closed 2024-02-14 · 40% similar
Microsec: Findings in 2023 Audit
#1983263 RESOLVED Audit Related Opened 2025-08-15 · Closed 2026-04-17 · 40% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #3 – Internal Audit

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action