Ga naar inhoud

2023-04 – Phishing and spoofing

Veld Waarde
Status Actief
Behandeling Accepteren
Kans Laag
Impact Hoog
Blootstelling Midden
Restblootstelling Laag
Eigenaar Management
Verantwoordelijke Security Officer

Asset

Confidential information stored in applications, financial assets

Dreiging

Service desk employees give access to unauthorized people, CEO fraud Our email domains are used for spoofing or phishing. As a result, 1. Customers get infected with malware 2. Customers enter credentials on malicious sites 3. Damage to our brand name/image

Risicocategorie

Vertrouwelijkheid, Integriteit

Risicoscore

Kans Impact Blootstelling Restblootstelling
Laag Hoog Midden Laag

Behandelingsmaatregelen

  • Create awareness on the risks of phishing and social engineering (A.6.3 Information security awareness, education and training)
  • Develop procedures e.g. for identity verification (A.5.37 Documented operating procedures)
  • Implement basic email security (SPF, DKIM and DMARC) (A.5.14 Information transfer/ A.8.24 Use of cryptography)

Gerelateerde documenten