Closed Bug 2008025 Opened 8 months ago Closed 7 months ago

PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #4 – Incident Management

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: Patrick.Berg, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Incident Management
  • Relevant Policies:
    • ETSI 319 401 (Clause 7.9)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → Patrick.Berg
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

The full incident report is in its final review stage and will be posted shortly.

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000068
  • Incident description: Incident management was not compliance with applicable requirements. Several non-conformities were identified related to the process itself. It was found P2 and P3 incidents were not managed using SLA, RTO and RPO. Escalation from P1 to P0 does occur, but a clear path, including linkage to BC, is missing from the process description. For internal incidents, no SLA was defined, and TRO/RPO of incidents are checked manually. The supply chain contractor does not include the RTO/RPO in their reports. Lastly, the IM manager has no delegate. On the operational side it was found one tickets had been closed before a lessons learned analysis was performed. Also, the follow-up of one incident was not properly managed.
  • Timeline summary:
    • Non-compliance start date: N/A
    • Non-compliance identified date: 26-Sep-2025
    • Non-compliance end date: Ongoing
  • Relevant policies:
    • ETSI 319 401 (Clause 7.9)
  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: N/A
  • Incident heuristic: N/A
  • Was issuance stopped in response to this incident, and why or why not?: N/A (see "additional considerations" below)
  • Analysis: N/A
  • Additional considerations: CIBG only operates legacy S/MIME-capable CAs but has never issued actual S/MIME-capable end-entity certificates. CIBG only issues certificates for use in the CIBG healthcare ecosystem.

Timeline

  • 26-Sep-2025: Auditor identifies finding
  • 23-Oct-2025: Created Corrective Action Plan
  • 06-11-2025: Corrective Action Plan Approved by auditor

Related Incidents

N/A

Root Cause Analysis

  • Contributing Factor 1: Insufficient QA on incident process description

    • Description: SLA, RTO and RPO of P2 and P3, as well as escalation paths are described in work instructions or embedded in tooling, and were not described in the incident process description itself. Also, the role of back-up or delegate of the incident manager has never explicitly been described in the incident process despite the incident manager having a back-up.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 2: Insufficient urgency for incident monitoring automation

    • Description: Historically resolution times were almost always in order, reducing the perception of urgency for automated monitoring.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 3: Insufficient QA on SLR report format

    • Description: During the development of more compact Service Level Requirements (SLR) report templates, certain performance indicators were inadvertently overlooked.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 4: Insufficient QA on problem management for problems at supplier.

    • Description: The agreed update frequency on problems at suppliers is insufficient to effectively support timely resolution.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A
  • What didn’t go well: N/A
  • Where we got lucky: N/A
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Redesign Incident Management process by Business Analysts Correct Root Cause #1 Check 2026-01-09 In progress
Adjust the yearly IM internal audit to zoom in on specific processes to be able to identify more specific improvement suggestions Prevent Root Cause #1, #3, #4 Check 2026-01-09 In progress
Improve the Problem Management process to better monitor backlog items Prevent Root Cause #2 Check 2026-01-09 In progress

Appendix

N/A

Assignee: Patrick.Berg → pkioverheid

All action items have been closed. A Report Closure Summary will be posted shortly.

Report Closure Summary

  • Incident description: Incident management was not compliance with applicable requirements. Several non-conformities were identified related to the process itself. It was found P2 and P3 incidents were not managed using SLA, RTO and RPO. Escalation from P1 to P0 does occur, but a clear path, including linkage to BC, is missing from the process description. For internal incidents, no SLA was defined, and TRO/RPO of incidents are checked manually. The supply chain contractor does not include the RTO/RPO in their reports. Lastly, the IM manager has no delegate. On the operational side it was found one tickets had been closed before a lessons learned analysis was performed. Also, the follow-up of one incident was not properly managed.
  • Incident Root Cause(s): SLA, RTO and RPO of P2 and P3, as well as escalation paths are described in work instructions or embedded in tooling, and were not described in the incident process description itself. Also, the role of back-up or delegate of the incident manager has never explicitly been described in the incident process despite the incident manager having a back-up. Historically resolution times were almost always in order, reducing the perception of urgency for automated monitoring. During the development of more compact Service Level Requirements (SLR) report templates, certain performance indicators were inadvertently overlooked. Insufficient QA on problem management for problems at supplier. The agreed update frequency on problems at suppliers is insufficient to effectively support timely resolution.
  • Remediation description: The Incident Management process a process has been redesigned to address the omissions. For the incident manager role replacement agreements have been formally recorded. In the supply chain the RTO and RPO performance indicators of P2 and P3 incidents are now included in the reporting. Additional agreements with the supplier on problem management update frequency have been made. In the internal audit plan specific processes and topics regarding incident management are now included to identity more specific improvement suggestions.
  • Commitment summary: In addition to the remediation description CIBG commits to adding to the internal audit plan the checking of the consistency between incident management, risk management and supply chain management processes.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-02-06.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2026-02-06] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2026-02-06] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.