PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #3 – Asset Management
This case is an incident report from PKIoverheid (CA Owner CCADB unique ID A000068) related to an ETSI audit finding about asset management. The annual ETSI audit identified a minor non-conformity: asset management did not include all identified critical and trustworthy assets operated by a supply chain contractor, and the asset list contained CIBG roles without mapping to Trusted Roles. The incident was disclosed to Mozilla as an annual ETSI audit finding. PKIoverheid described that, in a previous 2024 audit, it was stated that the contractor’s technical assets should not be mentioned in the CIBG Asset Overview, leading to those assets being omitted and contractor services being included only as a service; it also stated that role-to-Trusted Role mapping occurs in a separate document. The remediation included triggering a pre-audit inquiry with the auditor after big updates in standards or when changing auditors, and committing to adding to the internal audit plan checks for consistency between asset management, risk management, and supply chain management processes. The bug was resolved as FIXED, and the report closure summary stated that all action items were completed as described and closure was requested.
- An auditor identified a finding during the annual ETSI audit regarding asset management non-conformity.
- A corrective action plan was created in response to the audit finding.
- The corrective action plan was approved by the auditor.
- The incident report was scheduled to be closed if no further comments were received.
- Logius representative — Opened a preliminary incident report describing a minor non-conformity in asset management and noting the source as the annual ETSI audit.
- Logius representative — Stated the full incident report was in final review and would be posted shortly.
- Logius representative — Posted the full incident report, including the asset management issue, root cause analysis, timeline, and action items.
- Logius representative — Reported that all action items had been closed and that a report closure summary would be posted shortly.
- Logius representative — Posted the report closure summary, including remediation and a commitment to internal audit plan consistency checks, and requested closure.
- CCADB representative — Issued a final call for comments and stated the report would be closed on approximately 2026-02-06.