PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #4 – Incident Management
This case is an incident report from PKIoverheid (CA Owner CCADB unique ID A000068) regarding Incident Management non-conformities identified in a 2025 ETSI audit. The incident disclosure source is stated as a finding by the CAB during the annual ETSI audit. The report states that incident management was not compliant with applicable requirements (ETSI 319 401, Clause 7.9), including that P2 and P3 incidents were not managed using SLA, RTO, and RPO, and that escalation from P1 to P0 lacked a clear path with linkage to BC in the process description. It also reports that for internal incidents no SLA was defined, TRO/RPO were checked manually, the supply chain contractor did not include RTO/RPO in reports, and the incident manager had no delegate. On the operational side, it was found that one ticket was closed before a lessons learned analysis was performed and that follow-up of one incident was not properly managed. The CA states that the Incident Management process was redesigned, role replacement agreements were formally recorded, supplier reporting was updated to include RTO/RPO for P2 and P3, and additional agreements were made for problem management update frequency; action items were completed and the report closure summary requested closure. The bug is resolved as FIXED.
- An auditor identified an ETSI audit finding related to Incident Management non-conformities.
- A Corrective Action Plan was created in response to the finding.
- The Corrective Action Plan was approved by the auditor.
- The incident report’s action items were listed with due dates for remediation work.
- The CA reported that all action items had been closed and a report closure summary would follow.
- The CA posted the report closure summary describing remediation and requesting closure.
- The bug was marked RESOLVED with resolution FIXED.
- Logius representative — Opened a preliminary incident report describing a minor non-conformity in Incident Management and citing ETSI 319 401 (Clause 7.9) with disclosure sourced to the annual ETSI audit.
- Logius representative — Stated the full incident report was in final review and would be posted shortly.
- Logius representative — Posted the full incident report detailing multiple Incident Management non-conformities, root causes, a timeline, and action items with due dates and statuses.
- Logius representative — Reported that all action items had been closed and that a report closure summary would be posted shortly.
- Logius representative — Posted the report closure summary, describing remediation (process redesign, recorded role replacement agreements, supplier reporting updates, and audit plan updates) and requested closure.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed approximately 2026-02-06.