PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
This case is an incident report submitted by PKIoverheid (CA owner CCADB unique ID A000068) regarding a minor non-conformity found during KPN’s annual ETSI audit. The CAB reported that for the Disaster Recovery (DR) site, no active target actual document was available for certain network zones and that no firewall rulebase review and hardening review had been performed during the audit period. The issue was identified by the CAB during the annual ETSI audit and mapped to ETSI EN 319 401 requirements REQ-7.8-05 and REQ-7.8-06, with the report later updated to include Network and Certificate System Security Requirements section 1.2.2 – CA Infrastructure Security. PKIoverheid/KPN executed the DR firewall review (completed August 2025, no findings) and added process controls, including a check to ensure all environments are included in the firewall review schedule and updating the go-live checklist for periodic firewall review. In the thread, PKIoverheid stated that all action items were completed and requested closure. The bug was resolved as FIXED and marked RESOLVED.
- An auditor identified ETSI Finding #10 related to DR site firewall rules and review.
- A corrective action plan was created for the finding.
- The corrective action plan was approved by the auditor.
- The DR firewall review was executed and completed with no findings.
- The non-compliance end date was updated to reflect completion of the action items.
- The incident report bug was closed as RESOLVED (FIXED).
- Logius representative — Opened a preliminary incident report describing a minor non-conformity about DR firewall rules and review, disclosed as part of the annual ETSI audit.
- Logius representative — Posted the full incident report for ETSI Finding #10, including the CAB’s description, timeline, root cause analysis, and action items.
- Logius representative — Noted monitoring of the bug and that there were no updates on the action items at that time.
- Logius representative — Reported that action item #1 was completed earlier and that action item #2 was a duplicate of #3; stated all action items were completed.
- Apple representative — Asked whether NCSSRs were impacted and why they were not listed under “Relevant Policies.”
- Logius representative — Responded that NCSSRs were in scope for the audit and said the CAB’s omission for this finding was unclear, with KPN asking the CAB (BSI) for clarification.
- Logius representative — Provided BSI’s clarification and stated the bug would be updated to reflect applicable NCSSR criteria.
- Logius representative — Restated the incident report with updated applicable audit criteria including NCSSRs and updated the non-compliance end date and action items table.
- Logius representative — Submitted a report closure summary stating remediation steps taken, that all action items were completed, and requested closure.
- CCADB representative — Issued a final call for comments before the bug would be closed on approximately 2026-01-13.