PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #5 – CMDB
This case is an incident report submitted by PKIoverheid (Policy Authority PKIoverheid) regarding an ETSI audit finding related to CMDB (network asset inventory) evidence. The preliminary incident description states a minor non-conformity: CMDB registration of network assets. In the full incident report, PKIoverheid explains that during the audit, information about certain network assets was only provided to the CAB from a tool that does not log all relevant asset attributes, so the CAB could assess only incomplete data even though the information existed in the main CMDB. The CAB therefore filed a minor non-conformity that certain asset information was lacking, and PKIoverheid attributes the root cause to not requesting/assessing all required evidence during the audit. PKIoverheid reports corrective actions: updating procedures to use the default CMDB for newly required information, clearly identifying and validating the source of audit evidence ahead of audits, and providing guidance to relevant staff on preparing and presenting accurate documentation to auditors. The thread states that action items were completed and remediation is complete, with a request to close the bug; a final call for comments was issued with closure expected around 2025-11-19. The bug is marked RESOLVED with resolution FIXED.
- An ETSI audit identified a finding that CMDB-related evidence provided to the CAB lacked certain network asset attributes.
- A corrective action plan was created in response to the audit finding.
- The corrective action plan was approved by the auditor.
- PKIoverheid reported progress on the action items, including one completed and one in progress.
- PKIoverheid reported that action item #1 was completed and requested closure of the bug.
- CCADB incident reporting issued a final call for comments before closure.
- Logius representative — Opened the incident report with a preliminary description of a minor non-conformity regarding CMDB registration of network assets.
- Logius representative — Provided the full incident report for ETSI Finding #5 – CMDB, including root cause analysis and action items.
- Logius representative — Stated PKIoverheid was monitoring and had no updates on the action items at that time.
- Logius representative — Reported status updates: KPN completed action item #2, while action item #1 was in progress due to added complexity.
- Logius representative — Reported action item #1 completed, remediation complete, and requested closure shortly.
- Logius representative — Submitted a report closure summary stating remediation actions were completed and requested bug closure.
- CCADB representative — Issued a final call for comments and indicated the bug would be closed around 2025-11-19 if no further input was received.