PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #6 – Access Control Management
This case is an incident report from PKIoverheid (Policy Authority PKIoverheid) regarding findings from a 2025 ETSI audit for CIBG’s legacy S/MIME-capable TSP operations. The incident disclosure source is stated as the annual ETSI audit, where a CAB finding identified minor non-conformities in Access Control management. The report describes inconsistencies in the Access Control Management document (including an error in the number of trusted roles and an error in a formula defining conditions), lack of measures to assure revocation deadlines for trusted roles are met, and unavailability of all historical versions of the Access Control Management document. The report attributes contributing factors to insufficient QA on the Access Control document, limited scope of the document management process (initially only covering the CPS), and missing linkage between termination/transfer information and the Access Control process. Remediation included expanding the formal document management process to include the Access Control document and its QA, and automating pushes of termination/transfer information into the Access Control process to assure timely processing. The bug is marked RESOLVED with resolution FIXED, and the closure summary states that all action items were completed and requests closure.
- An auditor identified a finding related to Access Control management non-conformities during the ETSI audit.
- A Corrective Action Plan was created for the Access Control management incident.
- The Corrective Action Plan was approved by the auditor.
- The action item to expand formal document management to include the Access Control document and QA was completed.
- The action item to automate termination/transfer information pushes into the Access Control process was in progress.
- A report closure summary stated that all action items were completed and requested closure.
- Logius representative — Opened the preliminary incident report describing a minor non-conformity in Access Control Management and noting it was disclosed via the annual ETSI audit.
- Logius representative — Stated the full incident report was in final review and would be posted shortly.
- Logius representative — Posted the full incident report detailing Access Control document inconsistencies, revocation deadline assurance gaps, missing historical versions, root causes, and action items.
- Logius representative — Reported that all action items have been closed and that a report closure summary would be posted shortly.
- Logius representative — Posted the report closure summary with remediation details, commitment to internal audit checks, and a request to close the incident report.
- CCADB representative — Issued a final call for comments and stated the bug would be closed approximately 2026-02-06 if no questions were raised.