Closed Bug 2008026 Opened 8 months ago Closed 7 months ago

PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #5 – Risk Management

Categories

(CA Program :: CA Certificate Compliance, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: Patrick.Berg, Assigned: pkioverheid)

Details

(Whiteboard: [ca-compliance] [audit-finding])

Preliminary Incident Report

Summary

  • Incident Description:
    • Minor Non-conformity: Risk Management
  • Relevant Policies:
    • ETSI 319 401 (Clause 5)
  • Source of incident disclosure:
    • Annual ETSI Audit
Assignee: nobody → Patrick.Berg
Status: UNCONFIRMED → ASSIGNED
Type: defect → task
Ever confirmed: true
Whiteboard: [ca-compliance] [audit-finding]

The full incident report is in its final review stage and will be posted shortly.

Full Incident Report

Summary

  • CA Owner CCADB unique ID: A000068
  • Incident description: Several compliance issues were identified in the Risk Management process. The Risk Treatment plan lacked formal approvement and risk treatment measures were not clearly identified, nor their implementation status. Also several deficiencies were found in the Risk Assessment: not all components, TSP processes, standards, and technical sources of risk, were included. The Supply chain risk assessment is not complete and risks due to any open non-conformities were not part of the assessment. Lastly, the risk assessment only contained a version number in its file name.
  • Timeline summary:
    • Non-compliance start date: N/A
    • Non-compliance identified date: 26-Sep-2025
    • Non-compliance end date: Ongoing
  • Relevant policies:
    • ETSI 319 401 (Clause 5)
  • Source of incident disclosure: Finding by CAB during annual ETSI audit.

Impact

  • Total number of certificates: N/A
  • Total number of "remaining valid" certificates: N/A
  • Affected certificate types: N/A
  • Incident heuristic: N/A
  • Was issuance stopped in response to this incident, and why or why not?: N/A (see "additional considerations" below)
  • Analysis: N/A
  • Additional considerations: CIBG only operates legacy S/MIME-capable CAs but has never issued actual S/MIME-capable end-entity certificates. CIBG only issues certificates for use in the CIBG healthcare ecosystem.

Timeline

  • 26-Sep-2025: Auditor identifies finding
  • 23-Oct-2025: Created Corrective Action Plan
  • 06-11-2025: Corrective Action Plan Approved by auditor

Related Incidents

N/A

Root Cause Analysis

  • Contributing Factor 1: No CIBG-wide Risk Management process

    • Description: Currently there is no CIBG-wide Risk Management process, resulting in risk management from the operations-oriented TSP-team with residual risks not being formally approved by higher management
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 2: Insufficient QA on Risk Management process

    • Description: Because of a lacking CIBG-wide Risk Management process (see contributing factor 1), no outside QA was performed on the Risk Management deliverables from the operations-oriented TSP-team, resulting in several oversights over time.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A
  • Contributing Factor 3: Document Management process with limited scope

    • Description: At the moment, a formal document management process has only been drawn up for the Certification Practice Statement (CPS), as this is specifically required by ETSI. Document versioning and approval processes for other types of documents currently are not formalized.
    • Timeline: See main timeline.
    • Detection: Audit finding by CAB.
    • Interaction with other factors: No.
    • Root Cause Analysis methodology used: N/A

Lessons Learned

  • What went well: N/A
  • What didn’t go well: N/A
  • Where we got lucky: N/A
  • Additional: N/A

Action Items

Action Item Kind Corresponding Root Cause(s) Evaluation Criteria Due Date Status
Improve the Risk Management process with additional approved deliverables. As soon as an organization-wide process becomes available, both processes will need to connect. Prevent Root Cause #1 Check 2026-01-16 In progress
Schedule quarterly risk assessment QA review team members and approval by TSP manager Prevent Root Cause #2 Check 2026-01-12 In progress
Expand formal document management process to also include all risk management deliverables Correct Root Cause #3 Check 2026-01-16 In progress

Appendix

N/A

Assignee: Patrick.Berg → pkioverheid

All action items have been closed. A Report Closure Summary will be posted shortly.

Report Closure Summary

  • Incident description: Several compliance issues were identified in the Risk Management process. The Risk Treatment plan lacked formal approvement and risk treatment measures were not clearly identified, nor their implementation status. Also several deficiencies were found in the Risk Assessment: not all components, TSP processes, standards, and technical sources of risk, were included. The Supply chain risk assessment is not complete and risks due to any open non-conformities were not part of the assessment. Lastly, the risk assessment only contained a version number in its file name.
  • Incident Root Cause(s): Currently there is no CIBG-wide Risk Management process, resulting in risk management from the operations-oriented TSP-team with residual risks not being formally approved by higher management. Because of a lacking CIBG-wide Risk Management process (see contributing factor 1), no outside QA was performed on the Risk Management deliverables from the operations-oriented TSP-team, resulting in several oversights over time. At the moment of observation, a formal document management process had only been drawn up for the Certification Practice Statement (CPS), as this is specifically required by ETSI. Document versioning and approval processes for other types of documents currently are not formalized.
  • Remediation description: The Risk Management process has been improved with additional approved deliverables, including risks related to open non-conformities and the supply chain and the risk assessment review and approvement has been scheduled quarterly. The formal document management process has been expanded to include alle risk management deliverables.
  • Commitment summary: In addition to the remediation description CIBG commits to connect to an organization-wide risk management process further improving QA on risk management.

All Action Items disclosed in this report have been completed as described, and we request its closure.

This is a final call for comments or questions on this Incident Report.

Otherwise, it will be closed on approximately 2026-02-06.

Flags: needinfo?(incident-reporting)
Whiteboard: [ca-compliance] [audit-finding] → [close on 2026-02-06] [ca-compliance] [audit-finding]
Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Flags: needinfo?(incident-reporting)
Resolution: --- → FIXED
Whiteboard: [close on 2026-02-06] [ca-compliance] [audit-finding] → [ca-compliance] [audit-finding]
You need to log in before you can comment on or make changes to this bug.