Closed Bug 1983266 Opened 1 year ago Closed 9 months ago

PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #6 – Security Incident Procedure

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: pkioverheid, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Security Incident Procedure
  • Relevant Policies:
    • ETSI 319 401 (REQ-7.2-02, REQ-7.9.2-01X, -02X, -05X)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → pkioverheid
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

Full Incident Report - ETSI Finding #6 - Security Incident Procedure

Summary

  • CA Owner CCADB unique ID: A000068

  • Incident description: The CAB noticed that the handling of security incidents wasn’t in line with the established procedures and that the new security officer wasn’t properly informed and trained to establish the responsibilities in handling (escalating) security incidents. Also, the agreements with a subcontractor of KPN were not in line with the procedures established for handling security incidents at KPN. As such, registration and handling of security incidents wasn’t always in line with established procedures. This was noted down as a minor non-conformity.

  • Timeline summary:

    • Non-compliance start date: N/A

    • Non-compliance identified date: 11-Jul-2025

    • Non-compliance end date: Ongoing

  • Relevant policies:

    • ETSI 319 401 REQ-7.2-02: The TSP shall employ staff and, if applicable, subcontractors, who possess the necessary expertise, reliability, experience, and qualifications and who have received training regarding cybersecurity and personal data protection rules as appropriate for the offered services and the job function.

    • ETSI 319 401 REQ-7.9.2-01X: The TSP shall establish incident response procedures including containment, eradication and recovery.

    • ETSI 319 401 REQ-7.9.2-02X: The TSP shall comply with reporting obligations as mandated by relevant legislative frameworks for network and information security incidents, including supervisory authorities and CSIRTs.

    • ETSI 319 401 REQ-7.9.2-05X: The TSP shall ensure that personnel possess the necessary competencies to proficiently detect and respond to security incidents.

  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A

  • Total number of "remaining valid" certificates: N/A

  • Affected certificate types: N/A

  • Incident heuristic: N/A

  • Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)

  • Analysis: N/A

  • Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU emailProtection were no longer included in publicly trusted certificates.

Timeline

  • Feb-2025: Employment of new security officer.

  • 11-Jul-2025: Auditor identifies finding

  • 17-Jul-2025: Created Corrective Action Plan

  • 12-Aug-2025: Corrective Action Plan Approved by auditor

Related Incidents

Bug Date Description
1983264 15-Aug-2025 similar root cause (s).
1983256 15-Aug-2023 similar root cause(s).

Root Cause Analysis

Contributing Factor 1: Security Officer not fully briefed with regards to subcontractor responsibilities

  • Description: New KPN security officer was not fully informed on his role regarding security incidents occurring at a subcontractor.

  • Timeline: See main timeline.

  • Detection: Audit finding by CAB.

  • Interaction with other factors: N/A

  • Root Cause Analysis methodology used: N/A

Contributing Factor 2: Lack of alignment between internal procedures and contractual agreements with subcontractor

  • Description: The agreements with a subcontractor were not in line with the internal KPN (security) incident handling procedures.

  • Timeline: See main timeline

  • Detection: Audit finding by CAB.

  • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A

  • What didn’t go well: One security incident was not fully handled in line with the KPN in procedure.

  • Where we got lucky: N/A

  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Provide targeted briefing to the Security Officer on subcontractor responsibilities and incident handling protocols. Mitigate Root Cause #1 Executed briefing 2025-10-11 Complete
Ensure a proper handover process is established for key roles like the Security Officer, including documented responsibilities and ongoing tasks. Update procedures and documentation where needed and report back Root Cause #1 Check content 2025-10-11 Ongoing
For security incidents update procedure documentation in agreement with subcontractor. Prevent Root Cause # 2 Update agreements 2025-10-11 Ongoing

Appendix

N/A

In the Action items above an error had occured while pasting the information from internal systems to markdown, so an updated version with the right Evaluation Criteria is provided below. In the meantime, PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have.

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Provide targeted briefing to the Security Officer on subcontractor responsibilities and incident handling protocols. Mitigate Root Cause #1 Executed briefing to SO 2025-10-11 Complete
Ensure a proper handover process is established for key roles like the Security Officer, including documented responsibilities and ongoing tasks. Prevent Root Cause #1 Update procedures and documentation where needed and report back 2025-10-11 In progress
For security incidents update procedure documentation in agreement with subcontractor. Prevent Root Cause # 2 Align security procedure and subcontractor agreements and report back 2025-10-11 In progress

ETSI Finding #6 - Security Incident Procedure

As indicated earlier, action item #1 had already been completed earlier. In the meantime, action item #3 has been completed as well (documentation and procedures have been updated). The list of action items thereby is as follows:

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Provide targeted briefing to the Security Officer on subcontractor responsibilities and incident handling protocols. Mitigate Root Cause #1 Executed briefing to SO 2025-10-11 Completed
Ensure a proper handover process is established for key roles like the Security Officer, including documented responsibilities and ongoing tasks. Update procedures and documentation where needed and report back Root Cause #1 Update procedures and documentation where needed and report back 2025-10-11 In progress
For security incidents update procedure documentation in agreement with subcontractor. Prevent Root Cause # 2 Align security procedure and subcontractor agreements and report back 2025-10-11 Completed

Action item #2 has been completed. We're intending to submit a closure request shortly since remediation is complete, but in the meantime we're open to questions and/or comments that the community might have. Thanks.

Report Closure Summary

  • Incident description: The CAB noticed that the handling of security incidents wasn’t in line with the established procedures and that the new security officer wasn’t properly informed and trained to establish the responsibilities in handling (escalating) security incidents. Also, the agreements with a subcontractor of KPN were not in line with the procedures established for handling security incidents at KPN. As such, registration and handling of security incidents wasn’t always in line with established procedures. This was noted down as a minor non-conformity.
  • Incident Root Cause(s): There were two root causes: A new KPN security officer was not fully informed on his role regarding security incidents occurring at a subcontractor and there was a lack of alignment between internal procedures and contractual agreements with a specific subcontractor
  • Remediation description: KPN did take several remedation steps. A targeted briefing was provided to the Security Officer on subcontractor responsibilities and incident handling protocols, the handover process for key roles, including the Security Officer, has been revised to include documented responsibilities and recurring task and procedures for handling security incidents have been updated in coordination with subcontractors to ensure clarity and alignment in future cases.
  • Commitment summary: On top of the remediation actions KPN will execute periodic reviews of subcontractor arrangements and internal procedure to maintain consistency and compliance to prevent recurrence of this incident.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2025-11-19.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2025-11-19] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 9 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2025-11-19] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.