← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #2008024 Incident

PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #3 – Asset Management

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an incident report from PKIoverheid (CA Owner CCADB unique ID A000068) related to an ETSI audit finding about asset management. The annual ETSI audit identified a minor non-conformity: asset management did not include all identified critical and trustworthy assets operated by a supply chain contractor, and the asset list contained CIBG roles without mapping to Trusted Roles. The incident was disclosed to Mozilla as an annual ETSI audit finding. PKIoverheid described that, in a previous 2024 audit, it was stated that the contractor’s technical assets should not be mentioned in the CIBG Asset Overview, leading to those assets being omitted and contractor services being included only as a service; it also stated that role-to-Trusted Role mapping occurs in a separate document. The remediation included triggering a pre-audit inquiry with the auditor after big updates in standards or when changing auditors, and committing to adding to the internal audit plan checks for consistency between asset management, risk management, and supply chain management processes. The bug was resolved as FIXED, and the report closure summary stated that all action items were completed as described and closure was requested.

Model: gpt-5.4-nano Generated: 2026-06-13 21:18 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.86 6 comments
Chronology
  1. An auditor identified a finding during the annual ETSI audit regarding asset management non-conformity.
  2. A corrective action plan was created in response to the audit finding.
  3. The corrective action plan was approved by the auditor.
  4. The incident report was scheduled to be closed if no further comments were received.
Thread Activity
  1. Logius representative — Opened a preliminary incident report describing a minor non-conformity in asset management and noting the source as the annual ETSI audit.
  2. Logius representative — Stated the full incident report was in final review and would be posted shortly.
  3. Logius representative — Posted the full incident report, including the asset management issue, root cause analysis, timeline, and action items.
  4. Logius representative — Reported that all action items had been closed and that a report closure summary would be posted shortly.
  5. Logius representative — Posted the report closure summary, including remediation and a commitment to internal audit plan consistency checks, and requested closure.
  6. CCADB representative — Issued a final call for comments and stated the report would be closed on approximately 2026-02-06.
Participants
Logius representative CCADB representative
External References
Similar Local Cases
#1983267 RESOLVED Incident Opened 2025-08-15 · Closed 2026-03-30 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #7 – Change Management
#1983269 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-28 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #9 – Lifecycle Management
#1983270 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-13 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
#1983271 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-28 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #11 – Anti-Malware Software
#1983276 RESOLVED Incident Opened 2025-08-15 · Closed 2025-11-20 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #16 – EJBCA Configuration
#1985816 RESOLVED Incident Opened 2025-08-28 · Closed 2026-05-26 · 100% similar
PKIoverheid: TSP Cleverbase Findings in 2025 ETSI Audit - Incident Report #1 – Incorrect issuer CA listed in CPS
#2008021 RESOLVED Incident Opened 2025-12-30 · Closed 2026-02-09 · 100% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #1 – Document Management
#2008023 RESOLVED Incident Opened 2025-12-30 · Closed 2026-02-19 · 100% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #2 – Supply Chain Management

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action