2023-22 – Data leak or installation of malware at repair shop
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Laag |
| Impact | Hoog |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Security Officer |
Asset
Confidential data stored on mobile device (laptop, tablet or phone)
Dreiging
Repair shop gets access to (confidential data stored on) mobile device, data is leaked or malware is installed. The likelihood of this risk will increase with a BYOD policy, as users are inclined to choose a cheaper repair shop over an authorized dealer to repair a broken screen.
Risicocategorie
Vertrouwelijkheid, Integriteit
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Laag | Hoog | Midden | Laag |
Behandelingsmaatregelen
- Restrict repairs to authorized dealers only in Endpoint device policy (A.7.13 Equipment maintenance/ A.8.1 User endpoint devices)
- Add encryption and protection in Endpoint device policy (A.8.1 User endpoint devices/ A.8.24 Use of cryptography)
- Before having your device repaired, make sure all business related data is wiped
- (A.8.1. Endpoint device policy)