ICANN/DNSO
DNSO Mailling lists archives

[ga-full]


<<< Chronological Index >>>    <<< Thread Index >>>

RE: [ga] FYI: VeriSign audit report posted


Note that controls were in place continuously during the audit period (2001)
to ensure equivalent access but the auditors were not easily able to go back
to points in time in 2001 to verify that.  There are ways that this could
have been demonstrated but it would have been extremely expensive.  We are
waiting to see what recommendations the auditors make for dealing with this
in the future that would provide an easier way to verify historical
activity.

Chuck

-----Original Message-----
From: William X Walsh [mailto:william@wxsoft.info]
Sent: Tuesday, June 25, 2002 8:55 AM
To: Alexander Svensson
Cc: ga@dnso.org
Subject: Re: [ga] FYI: VeriSign audit report posted



Verisign's response seems reasonable and I would agree with its
conclusions as to the two violations noted (the IP address
restrictions and the labeling of data tapes).

However, their response did not seem to address this point:
Our examination also disclosed that VeriSign, Inc. had not established
adequate controls that would allow us to obtain sufficient evidence to
determine compliance with requirements H.V.1, H.V.2, H.V.4 and I.2 for
the year ended December 31, 2001 because VeriSign, Inc. did not
maintain sufficient historical records of system configuration
information on a daily basis. Because of this restriction on the scope
of our examination, we do not express an opinion on compliance with
Requirements H.V.1, H.V.2, H.V.4 and I.2 for the year ended December
31, 2001.


Tuesday, June 25, 2002, 2:02:08 AM, Alexander Svensson wrote:


> Report of Annual Independent Neutrality Audit
> http://www.icann.org/tlds/agreements/verisign/ain-audit-19jun02.htm

>>In our opinion, except for the material noncompliance and the restriction 
>>on the scope of our examination described above, VeriSign, Inc. complied, 
>>in all material respects, with the ICANN Requirements for the year ended 
>>December 31, 2001.

> VeriSign response
>
http://www.icann.org/tlds/agreements/verisign/verisign-ain-response-24jun02.
htm

>>As to the two minor areas of concern noted by the Auditors, we cannot
agree 
>>with the Auditors' conclusion that these items constituted "material 
>>noncompliance" with the stated requirements. 

> Best regards,
> /// Alexander

> --
> This message was passed to you via the ga@dnso.org list.
> Send mail to majordomo@dnso.org to unsubscribe
> ("unsubscribe ga" in the body of the message).
> Archives at http://www.dnso.org/archives.html





-- 
Best regards,
William X Walsh <william@wxsoft.info>
--
Save Internet Radio!  
CARP will kill Webcasting!
http://www.saveinternetradio.org/


--
This message was passed to you via the ga@dnso.org list.
Send mail to majordomo@dnso.org to unsubscribe
("unsubscribe ga" in the body of the message).
Archives at http://www.dnso.org/archives.html
--
This message was passed to you via the ga-full@dnso.org list.
Send mail to majordomo@dnso.org to unsubscribe
("unsubscribe ga-full" in the body of the message).
Archives at http://www.dnso.org/archives.html



<<< Chronological Index >>>    <<< Thread Index >>>