Telekom Security: Failure to file a bug for two findings from the 2024 Audit
Telekom Security GmbH disclosed that, during an ETSI audit in 2024, its auditors identified two findings that were already resolved during the audit, but Telekom Security failed to file a Bugzilla bug for them. Telekom Security stated that it overlooked the list of findings in the Audit Attestations, which it described as the decisive documents, and that it initially interpreted the findings as not requiring a bug because it believed there was no violation and only insufficient internal documentation. After a Root Store request on 2025-07-10 asking why the findings were not disclosed in a bug, Telekom Security disclosed a preliminary bug on 2025-07-11 and then provided a full incident report in this bug on 2025-07-17. The incident report describes two findings related to (1) documentation and implementation of a role appointment and access right process and (2) documentation and implementation of subcontractor management. Telekom Security provided action items to finalize documentation and to sensitize employees, and later stated that it completed the action items. The bug was requested for closure after all action items were completed, and CCADB indicated it would be closed on approximately 2025-08-20 if no further comments or questions were raised.
- ETSI audit attestations were published identifying two findings.
- A Root Store requested why Telekom Security did not disclose the audit findings in a bug.
- Telekom Security disclosed a preliminary incident bug in Bugzilla.
- Telekom Security disclosed the full incident report in the bug.
- Telekom Security stated it completed the action item to adapt audit and incident management processes and documentation.
- Telekom Security requested closure after completing all action items.
- Telekom representative — Opened the preliminary incident report stating Telekom Security failed to file a bug for two findings from the 2024 Audit and cited the relevant policies.
- Telekom representative — Provided the full incident report, explaining the two audit findings, why a bug was not filed initially, and the timeline including the Root Store request.
- Google representative — Requested additional detail on root cause analysis and action items, noting the report did not describe RCA/action items in the expected way.
- Telekom representative — Responded to feedback, provided an Audit Incident Report structure for both findings including root cause analysis and action items.
- Telekom representative — Reported completion of the action items and their statuses.
- Telekom representative — Submitted a report closure summary and requested closure, stating all action items were completed.
- CCADB representative — Issued a final call for comments or questions and stated the bug would be closed on approximately 2025-08-20.