Good questions...
Currently the process for pinging CAs for updated audit statements is
manual. Basically, when I have time I search through the spreadsheet to
see whose audit statements are out-of-date, and then send email to the
corresponding CAs. I have been trying to do this about 4 times per year,
so my records do get out of date. When I ping a CA, I usually find that
they already have a new audit statement, or find that their current
audit was slightly delayed due to scheduling or that they are still
waiting on the auditor for the official statements.
So, I don't think it's a matter of reminding CAs to do the annual audit.
I think it's a matter of reminding CAs to send me their updated audit
statements.
Thanks,
Kathleen
_______________________________________________
dev-security-policy mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-security-policy