2023-28 – Improper configuration/hardening
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Laag |
| Impact | Hoog |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Security Officer |
Asset
Confidential information stored on workstations or servers
Dreiging
A hacker gets access to systems due to 1. Unnecessary services running 2. Unnecessary ports open 3. Not following the supplier's hardening instructions
Risicocategorie
Vertrouwelijkheid, Integriteit, Beschikbaarheid
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Laag | Hoog | Midden | Laag |
Behandelingsmaatregelen
- Obtain hardening instructions from vendor/service provider (A.5.6 Contact with special interest groups)
- Periodically check security of systems (A.5.36 Compliance with policies and standards for information security)