PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #1 – Security Handbook
This case is an incident report from PKIoverheid (CA owner CCADB unique ID A000068) regarding a finding in a 2025 ETSI audit for the KPN TSP subCA. The CAB noted that procedures to ensure the KPN Security Handbook was up to date were not effective, including that certain parts of the document were out of date, resulting in a minor non-conformity. The incident was identified by the CAB during the annual ETSI audit, with the non-conformity identified on 11-Jul-2025 and described as ongoing at the time of the report. PKIoverheid/KPN created a Corrective Action Plan on 17-Jul-2025, updated the Security Handbook on 23-Jul-2025, and had the Corrective Action Plan approved by the auditor on 12-Aug-2025. The root cause analysis stated that the procedure for updating the documentation—specifically planning and scheduling—was not clearly defined or communicated, so a new temporary security officer was not aware of the requirement or timeline. PKIoverheid later reported that the action items were implemented and marked as completed, including rewriting the security handbook to reflect the review interval and instituting a periodic scheduled task to review it. The bug was requested for closure with a commitment to improve handover procedures for critical roles, including the Security Officer.
- An ETSI audit identified a finding that the KPN Security Handbook was not kept up to date due to ineffective update procedures.
- KPN created a Corrective Action Plan to remediate the audit finding.
- The KPN Security Handbook was updated.
- The auditor approved the Corrective Action Plan.
- PKIoverheid reported that the disclosed action items were implemented and marked completed.
- PKIoverheid submitted a closure summary requesting closure of the incident report.
- Logius representative — Opened a preliminary incident report stating the incident was a minor non-conformity that the Security Handbook was outdated, disclosed via the annual ETSI audit.
- Logius representative — Posted the full incident report describing the CAB finding, the root cause (update procedure not clearly defined/communicated), the timeline, and action items to update and schedule reviews of the Security Handbook.
- Logius representative — Noted that PKIoverheid was monitoring the bug and had no updates on the action items at that time.
- Logius representative — Provided an update that action items 1 and 2 were implemented, action item 3 had been completed once, and proposed marking it completed as well to avoid keeping the bug open for another 11 months.
- Logius representative — Submitted a report closure summary stating the Security Handbook was rewritten to reflect the review interval, a periodic scheduled task was instituted, and KPN committed to improve handover procedures for critical roles; requested closure.
- CCADB representative — Posted a final call for comments and indicated the bug would be closed on approximately 2025-11-19 if no further comments were received.