Ga naar inhoud

2023-22 – Data leak or installation of malware at repair shop

Veld Waarde
Status Actief
Behandeling Accepteren
Kans Laag
Impact Hoog
Blootstelling Midden
Restblootstelling Laag
Eigenaar Management
Verantwoordelijke Security Officer

Asset

Confidential data stored on mobile device (laptop, tablet or phone)

Dreiging

Repair shop gets access to (confidential data stored on) mobile device, data is leaked or malware is installed. The likelihood of this risk will increase with a BYOD policy, as users are inclined to choose a cheaper repair shop over an authorized dealer to repair a broken screen.

Risicocategorie

Vertrouwelijkheid, Integriteit

Risicoscore

Kans Impact Blootstelling Restblootstelling
Laag Hoog Midden Laag

Behandelingsmaatregelen

  • Restrict repairs to authorized dealers only in Endpoint device policy (A.7.13 Equipment maintenance/ A.8.1 User endpoint devices)
  • Add encryption and protection in Endpoint device policy (A.8.1 User endpoint devices/ A.8.24 Use of cryptography)
  • Before having your device repaired, make sure all business related data is wiped
  • (A.8.1. Endpoint device policy)

Gerelateerde documenten