2023-31 – Improper handling of information security incidents
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Midden |
| Impact | Midden |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Incident Manager |
Asset
Confidential information(systems)
Dreiging
Customers or employees do not know how to handle in case of an information security incident, as a result: 1. Forget to report it 2. Evidence is lost (logs are overwritten) 3. Incident is not (or improperly) treated 4. Incident is not (or too late) reported to relevant parties 5. No lessons are learned from the incident
Risicocategorie
Vertrouwelijkheid, Beschikbaarheid
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Midden | Midden | Midden | Laag |
Behandelingsmaatregelen
- Create an Incident management process (A.5.24 Information security incident management planning and preparation)
- Implement A.5.25 Assessment and decision on information security events
- Implement A.5.26 Response to information security incidents
- Implement A.5.27 Learning from information security incidents
- Implement A.5.28 Collection of evidence
- Remind people to report incidents in Code of conduct (A.6.8 Information security event reporting)
- Implement A.6.4 Disciplinary process