← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #1983270 Technical Compliance

PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review

CLOSED FIXED Government of The Netherlands, PKIoverheid (Logius)
AI Summary

The incident report details a minor non-conformity identified during an annual ETSI audit regarding the Disaster Recovery (DR) site's firewall rules and review process. It was noted that no active target document was available for certain network zones, and a firewall rulebase review had not been performed. KPN has since executed a firewall review, which yielded no findings, and has implemented measures to ensure all environments are included in future reviews. All action items related to this incident have been completed, and the report is now closed.

Model: gpt-4o-mini Generated: 2026-06-13 21:17 UTC Confidence: 0.95
Chronology
  1. Auditor identifies finding.
  2. Created Corrective Action Plan.
  3. Corrective Action Plan Approved by auditor.
  4. Firewall review executed, no findings.
  5. Non-compliance end date updated.
  6. Incident report closure.
Participants
Policy Authority PKIoverheid Dustin Hollenback Patrick Berg
External References
Similar Local Cases
#2008027 RESOLVED Technical Compliance Opened 2025-12-30 · Closed 2026-02-09 · 63% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #6 – Access Control Management
#1973034 RESOLVED Technical Compliance Opened 2025-06-19 · Closed 2025-07-02 · 40% similar
Certigna: Finding #3 ETSI Audit – Event log protection beyond seven years shall be improved
#1651611 RESOLVED Technical Compliance Opened 2020-07-09 · Closed 2023-02-22 · 40% similar
Telekom Security: Finding in 2020 ETSI-Audit regarding weekly review of changes to configurations
#1990274 RESOLVED Technical Compliance Opened 2025-09-23 · Closed 2026-05-04 · 40% similar
SwissSign: recommendation on synchronization of staging and production environments
#1684112 RESOLVED Technical Compliance Opened 2020-12-23 · Closed 2023-02-22 · 39% similar
Let's Encrypt: Failure to audit log subscriber certificate OCSP updates
#1990272 RESOLVED Technical Compliance Opened 2025-09-23 · Closed 2026-05-04 · 39% similar
SwissSign: recommendation on backup testing
#1830088 RESOLVED Technical Compliance Opened 2023-04-26 · Closed 2024-03-27 · 39% similar
Sectigo: Late termination of privileged access to Certificate Systems
#1914893 RESOLVED Technical Compliance Opened 2024-08-26 · Closed 2024-09-18 · 39% similar
Amazon Trust Services: CRL not DER-encoded

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action