Closed Bug 2008024 Opened 8 months ago Closed 7 months ago

PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #3 – Asset Management

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: Patrick.Berg, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Asset Management
  • Relevant Policies:
    • ETSI 319 401 (Clause 7.3)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → Patrick.Berg
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

The full incident report is in its final review stage and will be posted shortly.

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000068
  • Incident description: Asset management did not include all identified critical and trustworthy assets operated by a supply chain contractor. Also the asset list contained CIBG roles, but no mapping to Trusted Roles.
  • Timeline summary:
    • Non-compliance start date: N/A
    • Non-compliance identified date: 26-Sep-2025
    • Non-compliance end date: Ongoing
  • Relevant policies:
    • ETSI 319 401 (Clause 7.3)
  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: N/A
  • Incident heuristic: N/A
  • Was issuance stopped in response to this incident, and why or why not?: N/A (see "additional considerations" below)
  • Analysis: N/A
  • Additional considerations: CIBG only operates legacy S/MIME-capable CAs but has never issued actual S/MIME-capable end-entity certificates. CIBG only issues certificates for use in the CIBG healthcare ecosystem.

Timeline

  • 26-Sep-2025: Auditor identifies finding
  • 23-Oct-2025: Created Corrective Action Plan
  • 06-11-2025: Corrective Action Plan Approved by auditor

Related Incidents

N/A

Root Cause Analysis

  • Contributing Factor 1: Interpretation differences between auditors
    • Description: During the previous audit in 2024, it was stated that a (sub-)contractor's (technical) assets should not be mentioned in the Asset Overview of the CIBG. As a result, these are now missing from the overview and the services provided by (sub-)contractors are only included as a service in the asset overview. Likewise, mapping of CIBG roles to specific Trusted Roles also happens in a separate document.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A
  • What didn’t go well: N/A
  • Where we got lucky: N/A
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
After big updates in standards, or when changing auditors, trigger a pre-audit inquiry with the auditor on expectations regarding which information should be part of which document. Prevent Root Cause #1 Check 2025-12-01 Completed

Appendix

N/A

Assignee: Patrick.Berg → pkioverheid

All action items have been closed. A Report Closure Summary will be posted shortly.

Report Closure Summary

  • Incident description: Asset management did not include all identified critical and trustworthy assets operated by a supply chain contractor. Also, the asset list contained CIBG roles, but no mapping to Trusted Roles.
  • Incident Root Cause(s): During the previous audit in 2024, it was stated that a (sub-)contractor's (technical) assets should not be mentioned in the Asset Overview of the CIBG. As a result, these are now missing from the overview and the services provided by (sub-)contractors are only included as a service in the asset overview. Likewise, mapping of CIBG roles to specific Trusted Roles also happens in a separate document.
  • Remediation description: After big updates in standards, or when changing auditors, a pre-audit inquiry is triggered with the auditor on expectations regarding which information should be part of which document.
  • Commitment summary: In addition to the remediation description CIBG commits to adding to the internal audit plan the checking of the consistency between asset management, risk management and supply chain management processes.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-02-06.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2026-02-06] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2026-02-06] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.