PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #8 – Logical Access
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: Logical Access Review Scope
- Relevant Policies:
- ETSI 319 401 (REQ-7.4-07X)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #8 – Logical Access
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that a certain CA system was not in scope for the quarterly logical access review. This was included in the report/audit statement as a minor non-conformity.
-
Timeline summary:
-
Non-compliance start date: 2023
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: Ongoing
-
-
Relevant policies:
- ETSI 319 401 REQ-7.4-07X: The TSP shall review access rights to privileged and administrator accounts at planned intervals, and access rights shall be modified based on organisational changes. The result of the review, including the necessary changes of access rights, shall be documented.
-
Source of incident disclosure: Finding by CAB during annual ETSI audit
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates.
Timeline
-
2023: Application instance was added to the production environment.
-
11-Jul-2025: Auditor identifies finding
-
17-Jul-2025: Created Corrective Action Plan
-
25-Jul-2025: Recon executed.
-
12-Aug-2025: Corrective Action Plan Approved by auditor
Related Incidents
N/A
Root Cause Analysis
Contributing Factor 1: Logical access review scope not complete
-
Description: The application was not included in the target list (logical access review) because it uses the same access card as another application in the same environment. This led to the incorrect assumption that separate reconciliation was unnecessary for this application.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No.
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: The checks were already implicitly executed for a different application in the same environment.
-
What didn’t go well: At the time the application was added it was not noted that it must be added to the target list.
-
Where we got lucky: When the checks were executed no issues were identified.
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Add application instance to target list. | Mitigate | Root Cause #1 | Check target list for completeness | Complete | |
| Add check for updating target list to go-live checklist. | Prevent | Root Cause #1 | go-live checklist updated | 2025-10-11 | In progress |
| Periodically review the target list scope. | Detect | Root Cause #1 | periodic review has been completed successfully at least twice | 2025-10-11 |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
In the Action items above an error had occured while pasting the information from internal systems to markdown, so an updated version with the right Evaluation Criteria is provided below. In the meantime, PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have.
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Add application instance to target list. | Mitigate | Root Cause #1 | Check target list for completeness | N/A | Complete |
| Add check for updating target list to go-live checklist. | Prevent | Root Cause #1 | Update go-live checklist and report back | 2025-10-11 | In progress |
| Periodically review the target list scope. | Detect | Root Cause #1 | periodic review has been completed successfully at least twice | 2025-10-11 | In progress |
| Assignee | ||
Comment 3•11 months ago
|
||
We have some updates with regards to the action items:
- Action item #1 had been completed earlier.
- Action item #2 has been completed as well in the meantime.
- With regards to action item #3 the earlier stated due date is impossible to meet in so far that the recurring task has a frequency of 1x per year. This would mean that the item can only be completed twice by October 2026. The first review has been completed already. Since keeping this bug open for another year seems a bit overkill we propose marking this action item as completed as well.
The status of the action items is then as follows:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Add application instance to target list. | Mitigate | Root Cause #1 | Check target list for completeness | N/A | Completed |
| Add check for updating target list to go-live checklist. | Prevent | Root Cause #1 | go-live checklist updated | 2025-10-11 | Completed |
| Periodically review the target list scope. | Detect | Root Cause #1 | periodic review has been completed successfully at least twice | 2025-10-11 | Completed |
| Assignee | ||
Comment 4•10 months ago
|
||
Report Closure Summary
- Incident description: The CAB noted that a certain CA system was not in scope for the quarterly logical access review. This was included in the report/audit statement as a minor non-conformity.
- Incident Root Cause(s): The application was not included in the target list (logical access review) because it uses the same access card as another application in the same environment. This led to the incorrect assumption that separate reconciliation was unnecessary for this application.
- Remediation description: KPN has taken several steps to address the identified issues. These included adding the specific application Instance to the target list, including a check to update the target list to the go-live checklist for new systems and also implementation of a periodic review of the target scope
- Commitment summary: KPN commits to periodically evaluating and enhancing the logical access review process to align with best practices and regulatory requirements. Lessons learned from incidents will be incorporated into process updates.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 5•10 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2025-11-19.
Updated•9 months ago
|
Description
•