Ga naar inhoud

2023-29 – Usage of weak passwords

Veld Waarde
Status Actief
Behandeling Accepteren
Kans Laag
Impact Hoog
Blootstelling Midden
Restblootstelling Laag
Eigenaar Management
Verantwoordelijke Security Officer

Asset

Confidential information stored on (cloud) servers Unwanted access to confidential information, password

Dreiging

hacked or guessed, due to: 1. The use of insecure/weak passwords 2. Re-use of passwords 3. Phishing attempt

Risicocategorie

Vertrouwelijkheid, Integriteit

Risicoscore

Kans Impact Blootstelling Restblootstelling
Laag Hoog Midden Laag

Behandelingsmaatregelen

  • Require strong passwords in Password policy (A.5.17 Authentication information)
  • Encourage the use of password managers in Access control policy and Code of conduct (A.5.15 Access control)
  • Require 2FA for systems that contain sensitive information in Access control policy (A.5.17 Authentication information)
  • Create awareness on the risks of phishing and social engineering (A.6.3 Information security awareness, education and training)

Gerelateerde documenten