Re: Auditor letters and incident reports

2019-09-06 Thread Wayne Thayer via dev-security-policy
Thanks for the response Jeff. On Fri, Sep 6, 2019 at 4:17 PM jeffwardpki--- via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > On Wednesday, August 21, 2019 at 11:46:37 PM UTC-5, Jeremy Rowley wrote: > > Hey all, > > > > An interesting issue came up recently with audits. Be

Re: Auditor letters and incident reports

2019-09-06 Thread jeffwardpki--- via dev-security-policy
On Wednesday, August 21, 2019 at 11:46:37 PM UTC-5, Jeremy Rowley wrote: > Hey all, > > An interesting issue came up recently with audits. Because the Mozilla policy > includes some requirements that diverge from the BRs, the audit criteria > don't necessarily cover everything Mozilla cares abou

Re: Auditor letters and incident reports

2019-08-23 Thread clemens.wanko--- via dev-security-policy
Dear all, just a short note on that with regard to auditing and Audit Attestations based upon ETSI: throughout the audit we check the incidents of the current audit period as documented by the CA (have they been addressed at a sufficient level, have the measures taken proven that they are suffi

Re: Auditor letters and incident reports

2019-08-21 Thread Ryan Sleevi via dev-security-policy
On Thu, Aug 22, 2019 at 12:46 AM Jeremy Rowley via dev-security-policy < dev-security-policy@lists.mozilla.org> wrote: > Hey all, > > An interesting issue came up recently with audits. Because the Mozilla > policy includes some requirements that diverge from the BRs, the audit > criteria don't nec

RE: Auditor letters and incident reports

2019-08-21 Thread Jeremy Rowley via dev-security-policy
: Auditor letters and incident reports Hey all, An interesting issue came up recently with audits. Because the Mozilla policy includes some requirements that diverge from the BRs, the audit criteria don't necessarily cover everything Mozilla cares about. Thus, it's possible to have a

Auditor letters and incident reports

2019-08-21 Thread Jeremy Rowley via dev-security-policy
Hey all, An interesting issue came up recently with audits. Because the Mozilla policy includes some requirements that diverge from the BRs, the audit criteria don't necessarily cover everything Mozilla cares about. Thus, it's possible to have an incident that doesn't show up on an audit. It's