Telekom Security: ETSI audit finding (2020) about weekly review of configuration changes not being implemented for a specific system
Deutsche Telekom Security GmbH (Telekom Security) reported a compliance finding from a 2020 ETSI audit covering the Network and Certificate System Security Requirements (NCSSR), specifically the requirement for a weekly review of configuration changes. During the audit period (2020-03-23 to 2020-04-01), auditors found that one central network component/appliance was not compliant because neither the standard monitoring solution nor a comparable solution was implemented to fulfill the weekly review requirement. Telekom Security stated that, due to the system’s limited customizability, the standard monitoring client could not be installed, and an alternative process was later implemented. Telekom Security performed retrospective checks using log data and reported that there were no findings of unauthorized changes, and that no other systems were affected. A weekly review process by qualified personnel was established on 2020-04-15, and auditors later inspected the alternative solution on 2020-07-08 and determined it fulfilled NCSSR v1.3. Telekom Security also explained that they delayed posting the bug report and said they would not wait for future incident disclosures (or at least preliminary reports). The bug was resolved as FIXED.
- An ETSI audit identified a non-conformity: weekly review of configuration changes was not implemented for a specific central network component/appliance.
- Telekom Security established a weekly review of configuration changes by qualified personnel.
- Auditors inspected the alternative solution and determined it fulfilled NCSSR v1.3.
- The bug was intended to be closed after follow-up questions.
- Community commenter — Opened the bug describing the ETSI audit finding and Telekom Security’s remediation steps, including retrospective review and establishing a weekly review process.
- Mozilla representative — Asked for clarification on the incident timeline, whether changes were unauthorized, why reporting was delayed, and requested more incident-report detail per Mozilla’s template.
- Community commenter — Clarified that changes were authorized (the issue was that they would not be discovered in a weekly review), described the affected system, and explained why operations were continued.
- Community commenter — Provided a revised incident report based on the new template with a more detailed timeline and additional context.
- Community commenter — Requested details about how log data is maintained and trusted, and asked about controls supporting prompt reporting and script/script-disabling risks.
- Community commenter — Explained that logs are sent to a central tamper-proof log server, described protections for the automated script, and stated the core team would not wait to disclose future incident reports.
- Mozilla representative — Indicated no further questions and requested closing the bug on or about 27-Jan-2021.