PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #13 – Restore Test
Categories
(CA Program :: CA Certificate Compliance, task)
Tracking
(Not tracked)
People
(Reporter: pkioverheid, Assigned: pkioverheid)
Details
(Whiteboard: [ca-compliance] [audit-finding])
Preliminary Incident Report
Summary
- Incident Description:
- Minor Non-conformity: Restore Test Not Performed
- Relevant Policies:
- ETSI 319 401 (REQ-7.11.2-04X)
- Source of incident disclosure:
- Annual ETSI Audit
Updated•1 year ago
|
| Assignee | ||
Comment 1•1 year ago
|
||
Full Incident Report - ETSI Finding #13 - Restore Test
Summary
-
CA Owner CCADB unique ID: A000068
-
Incident description: The CAB noted that a backup/restore test hadn’t taken place during the period since the last audit visit. This was listed as a minor non-conformity on the audit statement.
-
Timeline summary:
-
Non-compliance start date:
-
Non-compliance identified date: 11-Jul-2025
-
Non-compliance end date: Ongoing.
-
-
Relevant policies:
- ETSI 319 401 REQ-7.11.2-04X: The TSP shall test at planned intervals the recovery of backup copies and redundancies and shall take corrective actions in case of findings. The results of these tests shall be documented.
-
Source of incident disclosure: Finding by CAB during annual ETSI audit.
Impact
-
Total number of certificates: N/A
-
Total number of "remaining valid" certificates: N/A
-
Affected certificate types: N/A
-
Incident heuristic: N/A
-
Was issuance stopped in response to this incident, and why or why not?: N/A (see point below)
-
Analysis: N/A
-
Additional considerations: KPN only operates legacy S/MIME-capable CAs, which have not issued any S/MIME certificates since 1 August 2023. At that time this was changed due to updated S/MIME regulations, under which email addresses and the EKU
emailProtectionwere no longer included in publicly trusted certificates. -
Incident heuristic: N/A
Timeline
-
28-Feb-2025: Effective date of version 3.1.1 of ETSI EN 319 401 which included updated and new requirements.
-
11-Jul-2025: Auditor identifies finding.
-
17-Jul-2025: Created Corrective Action Plan.
-
12-Aug-2025: Corrective Action Plan Approved by auditor.
Related Incidents
| Bug | Date | Description |
|---|---|---|
| 1983262 | 15-Aug-2025 | Similar root cause(s) |
| 1983271 | 15-Aug-2025 | Similar root cause(s) |
| 1983274 | 15-Aug-2025 | Similar root cause(s) |
Root Cause Analysis
Contributing Factor 1: Compliance management not fully effective
-
Description: Not all requirements were implemented in time, as the changes were not fully tracked or prioritized during the transition period, because there was no structured process in place to monitor updates. Responsibility for tracking and prioritizing these changes was not clearly assigned, which contributed to delays in implementation. Specific for this finding for business continuity is a hot backup site is available and tested periodically for recovery. The offline backup is not periodically tested as required in the new ETSI EN 319 401.
-
Timeline: See main timeline.
-
Detection: Audit finding by CAB.
-
Interaction with other factors: No.
-
Root Cause Analysis methodology used: N/A
Lessons Learned
-
What went well: N/A
-
What didn’t go well: N/A
-
Where we got lucky: No issues occurred when backups needed to be restored in annual DR test.
-
Additional: N/A
Action Items
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Schedule and execute comprehensive restore tests | Prevent | Root Cause #1 | Check if executed | 2025-10-11 | In progress |
| Execute gap analyses and implement remaining requirements | Prevent | Root Cause #1 | Check content | 2025-10-11 | In progress |
| Improve the structured process for tracking and implementing new requirements, including deadlines, periodic reviews and timely escalation to management. This includes assigning responsible persons for monitoring changes, and integrating updates into operational procedures. | Prevent | Root Cause #1 | Check content | 2025-10-11 | In progress |
| Discuss compliance requirements and the necessary resources in a recurring meeting with management. | Detect | Root Cause #1 | Check content | 2025-10-11 | Completed |
Appendix
N/A
| Assignee | ||
Comment 2•1 year ago
|
||
In the Action items above an error had occurred while pasting the information from internal systems to markdown, so an updated version with the right Evaluation Criteria is provided below. In the meantime, PKIoverheid is monitoring this bug and we're open for additional questions or remarks people might have.
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Schedule and execute comprehensive restore tests | Prevent | Root Cause #1 | Execution of checks and report back | 2025-10-11 | In progress |
| Execute gap analysis and implement remaining requirements | Prevent | Root Cause #1 | Analysis and implementation done, report back | 2025-10-11 | In progress |
| Improve the structured process for tracking and implementing new requirements, including deadlines, periodic reviews and timely escalation to management. This includes assigning responsible persons for monitoring changes and integrating updates into operational procedures. | Prevent | Root Cause #1 | Design and implement new procedures and report back | 2025-10-11 | In progress |
| Discuss compliance requirements and the necessary resources in a recurring meeting with management. | Detect | Root Cause #1 | Recurring meeting has been planned and has taken place at least twice | 2025-10-11 | In progress |
| Assignee | ||
Comment 3•11 months ago
|
||
We have some updates regarding this audit finding:
- Action items #2, #3 and #4 have been completed by KPN.
- Action item #1 is still planned to be completed by the due date.
The status of the action items is:
| Action Item | Kind | Corresponding Root Cause(s) | Evaluation Criteria | Due Date | Status |
|---|---|---|---|---|---|
| Schedule and execute comprehensive restore tests | Prevent | Root Cause #1 | Execution of checks and report back | 2025-10-11 | In progress |
| Execute gap analysis and implement remaining requirements | Prevent | Root Cause #1 | Analysis and implementation done, report back | 2025-10-11 | Completed |
| Improve the structured process for tracking and implementing new requirements, including deadlines, periodic reviews and timely escalation to management. This includes assigning responsible persons for monitoring changes and integrating updates into operational procedures. | Prevent | Root Cause #1 | Implement process and report back | 2025-10-11 | Completed |
| Discuss compliance requirements and the necessary resources in a recurring meeting with management. | Detect | Root Cause #1 | Recurring meeting has been planned and has taken place at least twice | 2025-10-11 | Completed |
| Assignee | ||
Comment 4•10 months ago
|
||
Action item #1 has been done (test has been executed). As such, remediation is complete. With that, we'll be submitting a closure request shortly, but in the meantime we're monitoring this bug for any questions and/or comments people might have. Thanks.
| Assignee | ||
Comment 5•10 months ago
|
||
Report Closure Summary
- Incident description: The CAB noted that a backup/restore test hadn’t taken place during the period since the last audit visit. This was listed as a minor non-conformity on the audit statement.
- Incident Root Cause(s): Not all requirements were implemented in time, as the changes were not fully tracked or prioritized during the transition period, because there was no structured process in place to monitor updates. Responsibility for tracking and prioritizing these changes was not clearly assigned, which contributed to delays in implementation.
- Remediation description: KPN has initiated several actions to strengthen its compliance processes which include the scheduling and execution of comprehensive restore tests and execution of a gap analysis for the remaining 401 requirements (and implementation of new requirements). The process for tracking and implementing new compliance requirements has been improved, including clear deadlines, assigned responsibilities, and escalation paths and compliance requirements and resource needs are now discussed in a recurring management meeting to ensure ongoing alignment and oversight.
- Commitment summary: KPN commits to strengthening system hygiene and operational consistency. For this specific issue, KPN will additionally implement automated backup-restore testing to ensure recoverability is continuously validated.
All Action Items disclosed in this report have been completed as described, and we request its closure.
Comment 6•10 months ago
|
||
This is a final call for comments or questions on this Incident Report.
Otherwise, it will be closed on approximately 2025-11-19.
Updated•9 months ago
|
Description
•