← Government of The Netherlands, PKIoverheid (Logius) cases
Bugzilla #2008027 Incident Audit Finding

PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #6 – Access Control Management

RESOLVED FIXED Government of The Netherlands, PKIoverheid (Logius)
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

This case is an incident report from PKIoverheid (Policy Authority PKIoverheid) regarding findings from a 2025 ETSI audit for CIBG’s legacy S/MIME-capable TSP operations. The incident disclosure source is stated as the annual ETSI audit, where a CAB finding identified minor non-conformities in Access Control management. The report describes inconsistencies in the Access Control Management document (including an error in the number of trusted roles and an error in a formula defining conditions), lack of measures to assure revocation deadlines for trusted roles are met, and unavailability of all historical versions of the Access Control Management document. The report attributes contributing factors to insufficient QA on the Access Control document, limited scope of the document management process (initially only covering the CPS), and missing linkage between termination/transfer information and the Access Control process. Remediation included expanding the formal document management process to include the Access Control document and its QA, and automating pushes of termination/transfer information into the Access Control process to assure timely processing. The bug is marked RESOLVED with resolution FIXED, and the closure summary states that all action items were completed and requests closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:19 UTC Revised: 2026-06-16 19:25 UTC Confidence: 0.84 6 comments
Chronology
  1. An auditor identified a finding related to Access Control management non-conformities during the ETSI audit.
  2. A Corrective Action Plan was created for the Access Control management incident.
  3. The Corrective Action Plan was approved by the auditor.
  4. The action item to expand formal document management to include the Access Control document and QA was completed.
  5. The action item to automate termination/transfer information pushes into the Access Control process was in progress.
  6. A report closure summary stated that all action items were completed and requested closure.
Thread Activity
  1. Logius representative — Opened the preliminary incident report describing a minor non-conformity in Access Control Management and noting it was disclosed via the annual ETSI audit.
  2. Logius representative — Stated the full incident report was in final review and would be posted shortly.
  3. Logius representative — Posted the full incident report detailing Access Control document inconsistencies, revocation deadline assurance gaps, missing historical versions, root causes, and action items.
  4. Logius representative — Reported that all action items have been closed and that a report closure summary would be posted shortly.
  5. Logius representative — Posted the report closure summary with remediation details, commitment to internal audit checks, and a request to close the incident report.
  6. CCADB representative — Issued a final call for comments and stated the bug would be closed approximately 2026-02-06 if no questions were raised.
Participants
Logius representative CCADB representative
External References
Similar Local Cases
#1983268 RESOLVED Incident Opened 2025-08-15 · Closed 2025-11-20 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #8 – Logical Access
#1983269 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-28 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #9 – Lifecycle Management
#1983270 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-13 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #10 – Firewall Rules and Review
#1983271 RESOLVED Incident Opened 2025-08-15 · Closed 2026-01-28 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #11 – Anti-Malware Software
#1983276 RESOLVED Incident Opened 2025-08-15 · Closed 2025-11-20 · 100% similar
PKIoverheid: TSP KPN Findings in 2025 ETSI Audit - Incident Report #16 – EJBCA Configuration
#1985816 RESOLVED Incident Opened 2025-08-28 · Closed 2026-05-26 · 100% similar
PKIoverheid: TSP Cleverbase Findings in 2025 ETSI Audit - Incident Report #1 – Incorrect issuer CA listed in CPS
#2008021 RESOLVED Incident Opened 2025-12-30 · Closed 2026-02-09 · 100% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #1 – Document Management
#2008023 RESOLVED Incident Opened 2025-12-30 · Closed 2026-02-19 · 100% similar
PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #2 – Supply Chain Management

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action