Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion CP-CPS.md
Original file line number Diff line number Diff line change
Expand Up @@ -1166,7 +1166,7 @@ ISRG is not required to publicly disclose any audit finding that does not impact

## 8.7 Self-Audits

ISRG performs a quarterly internal audit of at least a random 3% of issuance since the last WebTrust audit period. This audit includes linting of the selected certificates. Results are saved and provided to auditors upon request.
ISRG uses automated systems to perform a post-hoc self-audit of all certificates within 48 hours of their issuance in the normal case. Even in case of failure of those systems, ISRG guarantees that at least 3% of all certificates issued since the last self-audit undergo a self-audit at least quarterly. This audit includes linting of the selected certificates. Results are saved and provided to auditors upon request.
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should reword this so it's clear that a failure of the 100% system does not constitute a compliance issue.

"since the last self-audit undergo a self-audit" - should this say "undergoes"?

I also just don't really understand what this means to say about how we guarantee the 3% happens.


# 9. OTHER BUSINESS AND LEGAL MATTERS

Expand Down
Loading