Closed Bug 2008021 Opened 8 months ago Closed 7 months ago

PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #1 – Document Management

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: Patrick.Berg, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Document Management
  • Relevant Policies:
    • ETSI 319 401 (REQ-6.1-02, -06, -07, -08)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → Patrick.Berg
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

The full incident report is in its final review stage and will be posted shortly.

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000068
  • Incident description: TSP documents management not in compliance with the applicable requirements. Approval process, document status and version history was found to not be applied in a uniform manner on all process and work instructions. Also, a scanned autograph was used in a letter to a subscriber, but there was no formal process on using scanned autographs.
  • Timeline summary:
    • Non-compliance start date: N/A
    • Non-compliance identified date: 26-Sep-2025
    • Non-compliance end date: Ongoing
  • Relevant policies:
    • ETSI 319 401 (REQ-6.1-02, -06, -07, -08)
  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: N/A
  • Incident heuristic: N/A
  • Was issuance stopped in response to this incident, and why or why not?: N/A (see "additional considerations" below)
  • Analysis: N/A
  • Additional considerations: CIBG only operates legacy S/MIME-capable CAs but has never issued actual S/MIME-capable end-entity certificates. CIBG only issues certificates for use in the CIBG healthcare ecosystem.

Timeline

  • 26-Sep-2025: Auditor identifies finding
  • 23-Oct-2025: Created Corrective Action Plan
  • 06-11-2025: Corrective Action Plan Approved by auditor

Related Incidents

N/A

Root Cause Analysis

  • Contributing Factor 1: Interpretation of ETSI requirements

    • Description: At the moment, a formal process/work instruction has only been drawn up for the Certification Practice Statement (CPS), as this is specifically required by the standard. The CIBG does not have a policy for the drafting and approval of CIBG documents in general, resulting in no uniform working method.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 2: No awareness surrounding manual signature requirements in communication with subscribers

    • Description: There has never been a policy within the CIBG on which methods are allowed to sign letters to subscribers.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A
  • What didn’t go well: N/A
  • Where we got lucky: N/A
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Expand formal document management process to also include all work instructions and process documents related to PKI operations Correct Root Cause #1 Check 2026-01-16 In progress
Adopt gathered advice from Legal Department on signing letters in work instruction Correct Root Cause #2 Check 2026-01-16 In progress

Note: Since the root causes were based on misconceptions and a lack of awareness, preventive action were difficult to identify.

Appendix

N/A

Assignee: Patrick.Berg → pkioverheid

All action items have been closed. A Report Closure Summary will be posted shortly.

Report Closure Summary

  • Incident description: TSP documents management not in compliance with the applicable requirements. Approval process, document status and version history was found to not be applied in a uniform manner on all process and work instructions. Also, a scanned autograph was used in a letter to a subscriber, but there was no formal process on using scanned autographs.
  • Incident Root Cause(s): A formal process/work instruction has only been drawn up for the Certification Practice Statement (CPS), as this is specifically required by the standard. The CIBG does not have a policy for the drafting and approval of CIBG documents in general, resulting in no uniform working method and no awareness surrounding manual signature requirements in communication with subscribers.
  • Remediation description: CIBG has expanded the formal document management process to also include all work instructions and process documents related to PKI operations and adopted the legal advise regarding the use of manual signatures in work instructions.
  • Commitment summary: CIBG commits to periodically evaluating and updating the document management process, ensuring that all documents are reviewed in uniform and timely manner, and that responsibilities are clearly assigned.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-02-06.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2026-02-06] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2026-02-06] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.