PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #1 – Security Handbook
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: Security Handbook Outdated
- Relevant Policies:
- ETSI EN 319 401 (REQ-6.3-03, -06X)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #1 – Security Handbook
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that the procedures to ensure that the KPN Security Handbook were up to date not effective, e.g. certain parts of the document were out of date. This resulted in a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: N/A
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: Ongoing
-
Relevant policies:
-
ETSI EN 319 401 REQ-6.3-03: A TSP's information security policy shall be documented, implemented and maintained including the security controls and operating procedures for TSP's facilities, systems and information assets providing the services.
-
ETSI EN 319 401 REQ-6.3-06X: The TSP's information security policy and inventory of assets for information security (see clause 7.3) shall be reviewed at planned intervals or if significant changes occur to ensure their continuing suitability, adequacy and effectiveness
-
Source of incident disclosure: Finding by CAB during annual ETSI audit.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates.
Timeline
-
Q2-2024: Last update of security handbook.
-
Q1-2025: Change of security officer.
-
11-Jul-2025: Auditor Identifies finding
-
17-Jul-2025: KPN created a Corrective Action Plan to remediate the audit finding
-
23-Jul-2025: Security Handbook updated
-
12-Aug-2025: Corrective Action Plan Approved by auditor
Related Incidents
| Bug | Date | Description |
|------------------------------------|-----------------------------|------------------------------------------------------------------------|
| 1983264 | 15-Aug-2025 | Similar root cause (s). |
| 1983266 | 15-Aug-2025 | Similar root cause(s). |
Root Cause Analysis
Contributing Factor 1: Procedure for updating documentation not clearly defined
-
Description: During the audit, it was found that the Security Handbook was not up to date. This occurred because the procedure for updating the documentation, specifically, the planning and scheduling of these updates, was not clearly defined or communicated. As a result, the new/temporary security officer was not aware of the requirement or timeline to review and update the handbook. This indicates that the existing procedure (and planning) is not effective in ensuring that the Security Handbook remains current.
-
Timeline: See main timeline
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: The operations team has consistently followed the current security procedures set out in the handbook, so the impact was limited.
-
What didn’t go well: The formal security handbook had not been updated in a timely manner to account for the latest developments and requirements.
-
Where we got lucky: N/A
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
| ----------- | ---- | --------------------------- | ------------------- | -----------| ------ |
| Update security handbook. | Mitigate | Root Cause #1 | Report back when done | 2025-10-11 | Ongoing |
| Determine responsibilities regarding updating the security handbook, and document them in the security handbook. | Prevent | Root Cause #1 | Report back when done | 2025-10-11 | Ongoing |
| Schedule periodic task for reviewing the security handbook. | Prevent/Detect | Root Cause #1 | Periodic task has been triggered and executed at least twice | 2025-09-30 | Ongoing |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.
| Assignee | ||
Comment 3•11 months ago
|
||
With regards to the Action items we would like to provide an update. Both action items 1 and 2 have been implemented by KPN.
Action item 3 has been completed successfully once, but the next check isn’t due for another 11 months (the check is annual) so the proposed remediation date in our earlier post is not feasible. To keep the bug open for another 11 months seems like a bit of overkill so we propose to mark this action item as completed as well. This results in the following status:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Update security handbook. | Mitigate | Root Cause #1 | Report back when done | 2025-10-11 | Completed |
| Determine responsibilities regarding updating the security handbook, and document them in the security handbook. | Prevent | Root Cause #1 | Report back when done | 2025-10-11 | Completed |
| Schedule periodic task for reviewing the security handbook. | Prevent/Detect | Root Cause #1 | Periodic task has been triggered and executed at least twice | 2025-09-30 | Completed |
| Assignee | ||
Comment 4•10 months ago
|
||
Report Closure Summary
- Incident description: The CAB noted during the annual ETSI EN 319 411-1 audit for the PKIoverheid KPN TSP subCA that the procedures to ensure that the KPN Security Handbook were up to date not effective, e.g. certain parts of the document were out of date. This resulted in a minor non-conformity.
- Incident Root Cause(s): The procedure for updating the security handbook, specifically the planning and scheduling of these updates wasn’t clearly defined or communicated. Due to this, when a new (temporary) security officer was hired this subject wasn’t raised or communicated and as such the handbook wasn’t reviewed and updated within the time limits specified by ETSI EN 319 411-1
- Remediation description: Besides performing the annual update, KPN has also rewritten the security handbook to accurately reflect the review interval and has also instituted a periodic scheduled task to review the document which offers an automated reminder for the security officer
- Commitment summary: In addition to the immediate remediation actions, KPN commits to improve handover procedures for critical roles. This will include reviewing and enhancing onboarding and offboarding procedures for key roles, including (but not limited to) the Security Officer. This will ensure that role-specific responsibilities — such as document reviews, operational and compliance tasks — are consistently transferred and not overlooked during personnel changes.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 5•10 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2025-11-19.
Updated•9 months ago
|
Description
•