2023-04 – Phishing and spoofing
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Laag |
| Impact | Hoog |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Security Officer |
Asset
Confidential information stored in applications, financial assets
Dreiging
Service desk employees give access to unauthorized people, CEO fraud Our email domains are used for spoofing or phishing. As a result, 1. Customers get infected with malware 2. Customers enter credentials on malicious sites 3. Damage to our brand name/image
Risicocategorie
Vertrouwelijkheid, Integriteit
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Laag | Hoog | Midden | Laag |
Behandelingsmaatregelen
- Create awareness on the risks of phishing and social engineering (A.6.3 Information security awareness, education and training)
- Develop procedures e.g. for identity verification (A.5.37 Documented operating procedures)
- Implement basic email security (SPF, DKIM and DMARC) (A.5.14 Information transfer/ A.8.24 Use of cryptography)