2023-29 – Usage of weak passwords
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Laag |
| Impact | Hoog |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Security Officer |
Asset
Confidential information stored on (cloud) servers Unwanted access to confidential information, password
Dreiging
hacked or guessed, due to: 1. The use of insecure/weak passwords 2. Re-use of passwords 3. Phishing attempt
Risicocategorie
Vertrouwelijkheid, Integriteit
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Laag | Hoog | Midden | Laag |
Behandelingsmaatregelen
- Require strong passwords in Password policy (A.5.17 Authentication information)
- Encourage the use of password managers in Access control policy and Code of conduct (A.5.15 Access control)
- Require 2FA for systems that contain sensitive information in Access control policy (A.5.17 Authentication information)
- Create awareness on the risks of phishing and social engineering (A.6.3 Information security awareness, education and training)