PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #4 –Training
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: Training
- Relevant Policies:
- ETSI 319 401 (REQ-7.2-02, -04X, -05X)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #4 –Training
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noticed that there was no evidence available to indicate that new KPN employees had received the required training indicated by the security handbook. This was noted as a minor non-conformity
-
Timeline summary:
-
Non-compliance start date: N/A
-
Non-compliance identified date: 11-Aug-2025
-
Non-compliance end date: ongoing
-
-
Relevant policies:
-
ETSI 319 401 REQ-7.2-02: The TSP shall employ staff and, if applicable, subcontractors, who possess the necessary expertise, reliability, experience, and qualifications and who have received training regarding cybersecurity and personal data protection rules as appropriate for the offered services and the job function.
-
ETSI 319 401 REQ-7.2-04X: TSP's personnel should be able to fulfil the requirement of "expert knowledge, experience and qualifications" through formal training and credentials, or actual experience, or a combination of the two.
-
ETSI 319 401 REQ-7.2-05X: This should include regular (at least every 12 months) updates on new threats and current security practices.
-
-
Source of incident disclosure: Finding by CAB during annual ETSI audit.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates.
Timeline
-
Q1-2025: Change of security officer.
-
11-07-2025: Auditor identifies finding
-
17-07-2025: Created Corrective Action Plan
-
12-08-2025: Corrective Action Plan Approved by auditor
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 1983256 | 15-Aug-2023 | similar root cause(s). |
| 1983266 | 15-Aug-2025 | similar root cause(s). |
| 1983265 | 15-Aug-2025 | similar root cause(s). |
Root Cause Analysis
Contributing Factor 1: New employees did not follow required training
-
Description: During the audit, it was found that new employees had not completed the required training. This was due to the lack of a proper handover, as the previous security officer had left before a successor was hired, leading to a lack of continuity in tracking training compliance.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No.
-
Root Cause Analysis methodology used: N/A.
Contributing Factor 2: Audit evidence
-
Description: During the audit not all the required evidence was requested / assessed. Even though there was partial evidence of the required training being followed by the personnel this wasn’t discussed during the audit.
-
Timeline: N/A
-
Detection: N/A
-
Interaction with other factors: No
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: N/A
-
What didn’t go well: During the audit not all the required evidence was requested / assessed.
-
Where we got lucky: N/A
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| New employees will retroactively be trained. | Mitigate | Root Cause #1 | Report back on status training reports | 2025-10-11 | Ongoing |
| Ensure a proper handover process is established for key roles like the Security Officer, including documented responsibilities and ongoing tasks. | Prevent | Root Cause #1 | Document update and training completed | 2025-10-11 | Ongoing |
| Implement an integrated report to monitor training completion which can also be used as audit evidence. This report will be periodically discussed with management. | Prevent/Detect | Root Cause #1 | Report created and discussed with management | 2025-10-11 | Ongoing |
| Ensure the correct evidence source is clearly identified and validated prior to audits, and provide training or guidance to relevant staff on preparing and presenting accurate documentation to auditors. | Prevent | Root Cause # 2 | Update documentation and design/write guidance for personnel involved | 2025-10-11 | Ongoing |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have. Currently we don't have any updates with regards to the Action Items.
| Assignee | ||
Comment 3•11 months ago
|
||
We would like to give an update on the status of the Action items listed above. Action item #3 and #4 have been completed and action items #1 and #2 are currently still in progress. With that, the status of the action items is as follows:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| New employees will retroactively be trained. | Mitigate | Root Cause #1 | Report back on status training reports | 2025-10-11 | In progress |
| Ensure a proper handover process is established for key roles like the Security Officer, including documented responsibilities and ongoing tasks. | Prevent | Root Cause #1 | Document update and training completed | 2025-10-11 | In progress |
| Implement an integrated report to monitor training completion which can also be used as audit evidence. This report will be periodically discussed with management. | Prevent/Detect | Root Cause #1 | Report created and discussed with management | 2025-10-11 | Completed |
| Ensure the correct evidence source is clearly identified and validated prior to audits, and provide training or guidance to relevant staff on preparing and presenting accurate documentation to auditors. | Prevent | Root Cause # 2 | Update documentation and design/write guidance for personnel involved | 2025-10-11 | Completed |
| Assignee | ||
Comment 4•10 months ago
|
||
KPN has reported that action item #1 and #2 have been completed. As such, remediation is complete and we'll be requesting closing of this bug shortly. If there are any questions and/or comments we're monitoring this bug and will respond when needed.
| Assignee | ||
Comment 5•10 months ago
|
||
Report Closure Summary
- Incident description: The CAB noticed during the annual ETSI EN 319 411-1 audit that there was no evidence available to indicate that new KPN employees had received the required training indicated by the security handbook.
- Incident Root Cause(s): Due to insufficient handover when a new security officer was hired not all KPN CA personnel had followed required training that was indicated in the security handbook. While there was evidence that part of the personnel involved did follow the required training, this evidence wasn’t discussed or presented with the CAB during the annual audit.
- Remediation description: To prevent reoccurrence, the handover procedure for the security officer (and other key roles) were (re)written which included clearly defined responsibilities for one-off and recurring tasks. A monitoring task/display was also built which shows current training progress which can then be used to track compliance and as (internal) audit evidence. Employees were also trained to identify the correct information sources for relevant queries by the (internal) auditor.
- Commitment summary: KPN commits to maintaining oversight of personnel training compliance. Progress is periodically monitored via a dedicated agenda item in the monthly compliance meeting, ensuring that training requirements remain fulfilled and audit evidence is consistently available.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 6•10 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2025-11-19.
Updated•9 months ago
|
Description
•