2023-08 – Insufficient control of suppliers
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Midden |
| Impact | Midden |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Service Manager |
Asset
Confidential information stored in hosted/cloud applications
Dreiging
A supplier does not meet (contractual) requirements or service level agreement, does not comply to GDPR or ISO 27001 certification has expired.
Risicocategorie
Vertrouwelijkheid, Beschikbaarheid
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Midden | Midden | Midden | Laag |
Behandelingsmaatregelen
- Create a Supplier policy (A.5.19 Information security in supplier relationships)
- Maintain a register of Suppliers and their KPIs (A.5.20 Addressing information security within supplier agreements)
- Check compliance of these KPIs regularly (A.5.22 Monitoring, review and change management of supplier services)