PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #8 – Logical Access
This case is an incident report from PKIoverheid (Policy Authority PKIoverheid) regarding a logical access finding in a 2025 ETSI audit. The incident disclosure source was stated as an annual ETSI audit, where the CAB noted that a CA system was not in scope for the quarterly logical access review, recorded as a minor non-conformity. The report states that the non-conformity related to a logical access review scope issue starting in 2023, with the finding identified on 11-Jul-2025 and a corrective action plan created on 17-Jul-2025 and approved on 12-Aug-2025. The root cause analysis described that the application was not included in the target list because it used the same access card as another application, leading to an incorrect assumption that separate reconciliation was unnecessary. PKIoverheid/KPN remediation actions included adding the application instance to the target list, adding a check to update the target list to the go-live checklist, and implementing periodic review of the target scope. The thread reports that the action items were completed and requests closure, and the bug is marked RESOLVED with resolution FIXED.
- A CA-related application instance was added to the production environment, later identified as not being included in the quarterly logical access review scope.
- An auditor identified ETSI finding #8 regarding logical access review scope.
- A corrective action plan was created for the finding.
- The corrective action plan was approved by the auditor.
- PKIoverheid submitted a report closure summary stating remediation steps and that all action items were completed.
- The bug was resolved as FIXED.
- Logius representative — Opened a preliminary incident report describing a minor non-conformity for logical access review scope and citing ETSI 319 401 REQ-7.4-07X.
- Logius representative — Provided the full incident report for ETSI finding #8, including timeline, root cause analysis, and action items to update the logical access review scope.
- Logius representative — Noted an error in the pasted action-item evaluation criteria and provided an updated version, while stating monitoring and openness to questions.
- Logius representative — Updated action-item statuses, stating action items #1 and #2 were completed and proposing marking action item #3 as completed as well due to an adjusted feasible schedule.
- Logius representative — Submitted a report closure summary reiterating the incident description, root cause, remediation steps, and requesting closure after completion of all disclosed action items.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed on approximately 2025-11-19 if no further input was received.