Closed Bug 1983263 Opened 1 year ago Closed 4 months ago

PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #3 – Internal Audit

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: pkioverheid, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Internal Audit at subcontractor
  • Relevant Policies:
    • ETSI 319 401 (REQ-7.1.1-01, REQ-7.13-01, REQ-7.14.3-06X)
    • ETSI 319 403-1 (7.9d)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → pkioverheid
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

Full Incident Report - ETSI Finding #3 – Internal Audit

Summary

  • CA Owner CCADB unique ID: A000068

  • Incident description: The CAB noted that a required internal audit had not been performed at a KPN subcontractor. This was filed a minor non-conformity.

  • Timeline summary:

    • Non-compliance start date: N/A

    • Non-compliance identified date: 11-Jul-2025

    • Non-compliance end date: Ongoing.

  • Relevant policies:

    • ETSI 319 401 REQ-7.1.1-01: The TSP organization shall be reliable.

    • ETSI 319 401 REQ-7.13-01: The TSP shall ensure that it operates in a legal and trustworthy manner.

    • ETSI 319 401 REQ-7.14.3-06X [CONDITIONAL]: When the TSP makes use of a trust service component provided by another party it shall ensure that the security and functionality required by the trust service component meet the appropriate requirements of the applicable policy and practices

    • ETSI 319 403-1 7.9 (..) The following activities shall be part of surveillance audit: (..) d) review of internal audits and security management systems in place;

  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A

  • Total number of "remaining valid" certificates: N/A

  • Affected certificate types: N/A

  • Incident heuristic: N/A

  • Was issuance stopped in response to this incident, and why or why not?: N/A (see point below).

  • Analysis: N/A

  • Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU emailProtection were no longer included in publicly trusted certificates.

Timeline

  • 11-07-2025: CAB identifies finding

  • 17-07-2025: KPN created a Corrective Action Plan to remediate the audit finding

  • 12-08-2025: Corrective Action Plan Approved by auditor

Related Incidents

N/A

Root Cause Analysis

Contributing Factor 1: Agreements with subcontractor didn’t contain clauses regarding audit responsibility

  • Description: The internal audit at the supplier was not conducted due to a lack of clear agreements with the external party regarding audit responsibility.

  • Timeline: See main timeline.

  • Detection: Audit finding by CAB.

  • Interaction with other factors: No.

  • Root Cause Analysis methodology used: N/A

Contributing Factor 2: Internal audit schedule

  • Description: The audit was not included in the internal audit schedule, as supplier audits were not formally embedded in the planning process.

  • Timeline: See main timeline.

  • Detection: Audit finding by CAB.

  • Interaction with other factors: No.

  • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A

  • What didn’t go well: N/A

  • Where we got lucky: N/A

  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Execute specific internal audit Mitigate Root Cause #1 Check content 2025-10-11 Ongoing
Formalize agreements with external parties regarding audit responsibilities. Prevent Root Cause # 1 Check 2025-10-11 Ongoing
Ensure supplier audits are explicitly included in the internal audit schedule going forward. Prevent Root Cause # 2 Check 2025-09-30 Ongoing

Appendix

N/A

In the Action items above an error had occured while pasting the information from internal systems to markdown, so an updated version with the right Evaluation Criteria is provided below. In the meantime, PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have.

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Execute specific internal audit Mitigate Root Cause #1 Report back when audit has been concluded 2025-10-11 In progress
Formalize agreements with external parties regarding audit responsibilities. Prevent Root Cause # 1 Report back when agreements have been updated 2025-10-11 In progress
Ensure supplier audits are explicitly included in the internal audit schedule going forward. Prevent Root Cause # 2 Report back when this has been implemented 2025-09-30 In progress

After discussing matters with the involved subcontractor, the decision has been made to execute a full external audit on the subcontractor in question. Since this required a longer lead time than the original plan to execute an internal audit (performed by a KPN internal auditor) the remedation will take longer. The expected due date of the external audit is now 01-01-2026. With that, the status of the action item is as follows:

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Execute specific internal audit Mitigate Root Cause #1 Check content 2025-10-11 Won't do
Formalize agreements with external parties regarding audit responsibilities. Prevent Root Cause # 1 Report back 2025-10-11 In progress
Ensure supplier audits are explicitly included in the internal audit schedule going forward. Prevent Root Cause # 2 Report back 2025-09-30 Won't do
Execute external audit by subcontractor. Subcontractor reports results back to KPN and Logius Prevent Root Cause #1&#2 Report back results 01-01-2026 In progress

Action items 2 has been completed. We erroneously reported action item #3 as a won't do above, KPN has updated the internal audit schedule with regards to supplier audits in general.

As such, only action item #4 is still open.

This report has gone stale.

You may request a next update that's beyond the normal weekly cadence but, absent that being accepted, you are required to provide an update on a weekly basis.

The visits of the external auditor at the subcontractor now has been scheduled, but was not possible earlier than the last week of January and first week of February. The expected due date of the external audit therefore has shifted to 2026-02-09. With that, the status of the action item is as follows:

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Execute specific internal audit Mitigate Root Cause #1 Check content 2025-10-11 Won't do
Formalize agreements with external parties regarding audit responsibilities. Prevent Root Cause # 1 Report back 2025-10-11 Completed
Ensure supplier audits are explicitly included in the internal audit schedule going forward. Prevent Root Cause # 2 Report back 2025-09-30 Completed
Execute external audit by subcontractor. Subcontractor reports results back to KPN and Logius Prevent Root Cause #1 & #2 Report back results 2026-02-09 In progress

This report has gone stale. As a reminder, CA Owners may request the “Next update” Whiteboard field be set by a Root Store Operator to align with a specific date related to an open Action Item.

Flags: needinfo?(pkioverheid)

Implementation is on schedule. No further updates.

Flags: needinfo?(pkioverheid)

This report, along with another PKIoverheid report, has gone stale.

We strongly encourage you to request the "Next update" Whiteboard field be set to align with a specific date related to the soonest appearing open Action Item. Unless a "Next update" date is set, the CCADB Incident Reporting Guidelines establish an expectation of CA Owners providing weekly status updates.

Flags: needinfo?(pkioverheid)

Could the "Next Update" for this bug be set to 2026-02-09? We were unsure if this was needed or not, in the past this action had been done by the triage owner based on the action items. We'll take this into account for future bugs and will update our own internal procedures for this. Thanks.

Flags: needinfo?(pkioverheid)
Whiteboard: [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding] Next update 2026-02-09

Please provide an update. Thanks.

Flags: needinfo?(pkioverheid)
Whiteboard: [ca-compliance] [audit-finding] Next update 2026-02-09 → [ca-compliance] [audit-finding]

The audit is currently in progress, the start was slightly delayed due to the fact that the audit in this form was new for the subcontractor involved and as such required more time to set up. This has also led to a different approach compared to a normal annual audit which means a two staged audit with a gap in between for remediating non-conformities (if present). Since the audit is currently in stage 1, the end date for the whole (including certification) is currently unknown, so we can't really give a firm due date for action item #4.

Since the main root causes were already addressed by action items #2 and #3 (which have been completed) we think that this bug can be closed, since the evaluation criteria for action item #4 was always only going to be self-reporting which wouldn't add much more in this public report, looking back. The follow-up for this action item would be covered both by the KPN CAB and also by the engaged CAB for the subcontractor for which regulatory frameworks exist (like ETSI EN 319 403 etc.).

Flags: needinfo?(pkioverheid)

PKIoverheid is currently monitoring this bugs for any questions and/or comments that the community or browsers might have. As stated above, we believe that the remaining action item, while still in progress, doesn't contribute to addressing the root cause(s) which caused this non-compliance (and hence this bug). If anyone has any comments, questions or objections to this approach, please feel free to state those in this bug.

We would like to give the community the option to respond to our last statement and voice any comments and/or questions they might have about this approach. If there is no response or input, we would like to proceed by filing a closure request next week (that is, Monday March 16) unless of course there is new information, questions or objections.

Since no objections or comments have been raised we propose to close this bug as indicated in comment #14. As such, please find the closure summary below.


Report Closure Summary

  • Incident description: The CAB of TSP KPN (subCA of PKIoverheid) noted during an audit visit that no (internal) audit had been performed at one of its subcontractors
  • Incident Root Cause(s): Auditing responsibility wasn't included in the contract between KPN and the involved subcontractor. It was also found that auditing at subscontractors wasn't included in the KPN internal audit schedule.
  • Remediation description: Agreemeents with subcontractors have been updated to include auditing responsibilities and subcontractor/supplier audits are explicitly included in the (internal) audit schedule of KPN. An external audit of the involved subcontractor is in progress.
  • Commitment summary: KPN commits itself to have a proactive approach to subcontractor compliance which include executing (internal) audits in a timely fashion and acting upon the results.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-04-16.

Whiteboard: [ca-compliance] [audit-finding] → [close on 2026-04-16] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 4 months ago
Resolution: --- → FIXED
Whiteboard: [close on 2026-04-16] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.