Ga naar inhoud

2023-08 – Insufficient control of suppliers

Veld Waarde
Status Actief
Behandeling Accepteren
Kans Midden
Impact Midden
Blootstelling Midden
Restblootstelling Laag
Eigenaar Management
Verantwoordelijke Service Manager

Asset

Confidential information stored in hosted/cloud applications

Dreiging

A supplier does not meet (contractual) requirements or service level agreement, does not comply to GDPR or ISO 27001 certification has expired.

Risicocategorie

Vertrouwelijkheid, Beschikbaarheid

Risicoscore

Kans Impact Blootstelling Restblootstelling
Midden Midden Midden Laag

Behandelingsmaatregelen

  • Create a Supplier policy (A.5.19 Information security in supplier relationships)
  • Maintain a register of Suppliers and their KPIs (A.5.20 Addressing information security within supplier agreements)
  • Check compliance of these KPIs regularly (A.5.22 Monitoring, review and change management of supplier services)

Gerelateerde documenten