← Chunghwa Telecom cases
Bugzilla #2009043
CCADB Compliance
Chunghwa Telecom: Delayed disclosure to Bug 2008782 GTLSCA Audit Incident Report #1 - mass certificate revocation plan
RESOLVED
FIXED
Chunghwa Telecom
AI Summary
Chunghwa Telecom experienced a delayed disclosure incident related to an audit finding from the GTLSCA annual audit report received on December 13, 2025. The finding, which was not disclosed in a public incident report until January 6, 2026, was reported by a third party, prompting corrective action. The delay was attributed to insufficient understanding of CCADB Policy 5.2, which mandates disclosure of audit findings within 72 hours. Chunghwa Telecom has since implemented measures to improve compliance, including mandatory training and the establishment of an audit monitoring dashboard.
Chronology
- Start of non-compliance due to missed disclosure window
- Non-compliance identified
- End of non-compliance
- Case closure requested
Participants
Tsung-Min Kuo
External References
Similar Local Cases
Chunghwa Telecom: Delayed disclosure to Bug 2008799 GTLSCA Audit Incident Report #3 - Missing vulnerability scan
Chunghwa Telecom: Delayed audit disclosure for GTLSCA
Chunghwa Telecom: Delayed Annual Audit Report 2024
Chunghwa Telecom: Delayed to Submit Annual CCADB Self-Assessment 2024 by GTLSCA.
Chunghwa Telecom: Failure to Submit Annual CCADB Self-Assessment 2023 by GTLSCA.
Chunghwa Telecom: Delayed disclosure to Bug 2008803 GTLSCA Audit Incident Report #4 - Missing evaluation for third parties
Certigna: Delay in reporting an audit finding
Telia: Delayed submission of preliminary audit incident report