Closed Bug 2008023 Opened 8 months ago Closed 6 months ago

PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #2 – Supply Chain Management

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: Patrick.Berg, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Supply Chain Management
  • Relevant Policies:
    • ETSI 319 401 (Clause 7.14)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → Patrick.Berg
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

The full incident report is in its final review stage and will be posted shortly.

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000068
  • Incident description: Not all Supply Chain Management requirements were found to be part of contracts with suppliers. Also, no general Supply Chain Management Policy was found. It was also noticed there was no reference to the possible use of time stamp, and a delay in the analysis of an SLA report was observed. Further observations were a lack of details in pentest and vulnerability tests requirements, and limited visibility and management of sub-contractors and their non-conformities.
  • Timeline summary:
    • Non-compliance start date: N/A
    • Non-compliance identified date: 26-Sep-2025
    • Non-compliance end date: Ongoing
  • Relevant policies:
    • ETSI 319 401 (Clause 7.14)
  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: N/A
  • Incident heuristic: N/A
  • Was issuance stopped in response to this incident, and why or why not?: N/A (see "additional considerations" below)
  • Analysis: N/A
  • Additional considerations: CIBG only operates legacy S/MIME-capable CAs but has never issued actual S/MIME-capable end-entity certificates. CIBG only issues certificates for use in the CIBG healthcare ecosystem.

Timeline

  • 26-Sep-2025: Auditor identifies finding
  • 23-Oct-2025: Created Corrective Action Plan
  • 06-11-2025: Corrective Action Plan Approved by auditor

Related Incidents

N/A

Root Cause Analysis

  • Contributing Factor 1: ETSI Supply Chain Management requirements did not yet exist when contracts with suppliers were formalized
    • Description: Because the ETSI Supply Chain Management requirements did not yet exist when contracts with suppliers were formalized, only the standard governmental clauses on Supply Chain Management were included. Later requirements were formalized in internal policies and only retrofitted in SLAs and DAPs with suppliers.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 2: CIBG does not offer an organization-wide policy on Supply Chain Management
    • Description: Since the ETSI Supply Chain Management requirements only apply to the TSP department of CIBG, there is no need to implement these organization-wide and for which already standardized governmental requirements exist.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 3: Time Stamping service is not offered by CIBG
    • Description: Because no Time Stamping service is offered by CIBG, requirements on its usage are not described.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 4: Lack of awareness in reporting on analysis and discussion of SLA reports
    • Description: SLA report was delivered on time and was analyzed on time. CIBG and its supplier agreed upon postponing discussing the analysis due to circumstances but did not duly document this.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 5: Levels of detail related to pentest and vulnerability reporting not formalized
    • Description: Full pentests details are delivered to the security section due to contractual obligations. The TSP department only receives a management overview. This is also the case for vulnerability scan reports. However, the required level of detail needed for the TSP department has never been formalized.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 6: Status of sub-contractor only visible through yearly Supervisory visit at suppliers
    • Description: Suppliers are responsible for resolving findings at sub-suppliers and that is the reason why these findings were not part of their regular status updates.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A
  • What didn’t go well: N/A
  • Where we got lucky: N/A
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Discuss with auditors beforehand which new requirements should be retrofitted in contracts if DAPs and SLAs do not suffice. Prevent Root Cause #1 Check 2026-01-16 In progress
Draw up organization-wide policy regarding Supply Chain Management Correct Root Cause #2 Check 2026-01-16 In progress
Document requirements on the use of time stamping services from other service providers in the formal supply chain documentation and amend the CPS. Correct Root Cause #3 Check 2026-01-16 In progress
Expand the Service Level Management process with requirements on administrating timestamps for SLM process steps and any delays Correct Root Cause #4 Check 2026-01-16 In progress
Formalize the level of detail needed in pentest and vulnerability test reporting Correct Root Cause #5 Check 2026-01-16 In progress
Formalize agreements with suppliers on reporting on the follow-up of findings at sub-suppliers Correct Root Cause #6 Check 2026-01-16 In progress

Appendix

N/A

Assignee: Patrick.Berg → pkioverheid

The first four action items have been closed. Finalizing the last two action items takes longer due to underestimation of the various legal and contractual hurdles in the supply chain. The action items haven been updated in the table below.

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Discuss with auditors beforehand which new requirements should be retrofitted in contracts if DAPs and SLAs do not suffice. Prevent Root Cause #1 Check 2026-01-16 Closed
Draw up organization-wide policy regarding Supply Chain Management Correct Root Cause #2 Check 2026-01-16 Closed
Document requirements on the use of time stamping services from other service providers in the formal supply chain documentation and amend the CPS. Correct Root Cause #3 Check 2026-01-16 Closed
Expand the Service Level Management process with requirements on administrating timestamps for SLM process steps and any delays Correct Root Cause #4 Check 2026-01-16 Closed
Formalize the level of detail needed in pentest and vulnerability test reporting Prevent Root Cause #5 Check 2026-02-05 In progress
Formalize agreements with suppliers on reporting on the follow-up of findings at sub-suppliers Prevent Root Cause #6 Check 2026-02-05 In progress

Implementation is on schedule. No further updates.

Report Closure Summary

  • Incident description: Not all Supply Chain Management requirements were found to be part of contracts with suppliers. Also, no general Supply Chain Management Policy was found. It was also noticed there was no reference to the possible use of time stamp, and a delay in the analysis of an SLA report was observed. Further observations were a lack of details in pentest and vulnerability tests requirements, and limited visibility and management of sub-contractors and their non-conformities.
  • Incident Root Cause(s): Because the ETSI Supply Chain Management requirements did not yet exist when contracts with suppliers were formalized, only the standard governmental clauses on Supply Chain Management were included. Later requirements were formalized in internal policies and only retrofitted in SLAs and DAPs with suppliers. Since the ETSI Supply Chain Management requirements only apply to the TSP department of CIBG, there is no need to implement these organization-wide and for which already standardized governmental requirements exist. SLA report was delivered on time and was analyzed on time. CIBG and its supplier agreed upon postponing discussing the analysis due to circumstances but did not duly document this. Full pentests details are delivered to the security section due to contractual obligations. The TSP department only receives a management overview. This is also the case for vulnerability scan reports. However, the required level of detail needed for the TSP department has never been formalized. Suppliers are responsible for resolving findings at sub-suppliers and that is the reason why these findings were not part of their regular status updates.
  • Remediation description: Discuss with auditors beforehand which new requirements should be retrofitted in contracts if DAPs and SLAs do not suffice. An organization-wide policy regarding Supply Chain Management has been drawn up. Requirements on the use of time stamping services from other service providers are documented in the formal supply chain documentation and in the next CPS. The Service Level Management process has been expanded with requirements on administrating timestamps for SLM process steps and any delays. Further agreements with suppliers on reporting on the follow-up of findings at sub-suppliers and the level of detail needed in pentest and vulnerability test reporting have been made.
  • Commitment summary: In addition to the remediation description CIBG commits to adding to the internal audit plan the supply chain management with special focus on the reporting from the suppliers on pentesting, vulnerabilities and status reporting on (sub-) supplier findings.

All Action Items disclosed in this report have been completed as described, and we request its closure.

Hello PKIoverheid,

The “Relevant Policies” section lists only ETSI EN 319 401 (Clause 7.14). Please confirm whether you evaluated this incident against all other applicable requirements, including the S/MIME Baseline Requirements and Network Security Requirements. If you concluded that no other requirements were affected, please explain the basis for that determination.

Thank you.

Hi Dustin,

Previous versions of ETSI EN 319 401 were largely based on PKI best practices as described in CABF documents and roughly follow the structure of RFC 3647 section 4.5. Only after the introduction of the European directive NIS2, which also applies to European TSPs (meaning PKIoverheid as well), ETSI EN 319 401 v3.1.1 included a new clause 7.14. This clause contains up to 30 very specific requirements related to supply chain management. Therefore it is not possible to map those to the SBR or NetSec specifically. The problem was not that agreements were not in place (which could be loosely mapped to SBR 8.8 "Review of delegated parties"), but the auditor was of the opinion that not all of these agreements were in line with some very specific NIS2 requirements in Clause 7.14.

Patrick

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-02-19.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2026-02-19] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 6 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2026-02-19] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.