2023-32 – Unwanted access to confidential information in working areas
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Laag |
| Impact | Midden |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Security Officer |
Asset
Confidential information used in areas of work (e.g. office, home, customer sites)
Dreiging
Guests, cleaners or even uninvited people steal, modify or leak confidential information found in offices
Risicocategorie
Vertrouwelijkheid, Integriteit, Beschikbaarheid
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Laag | Midden | Midden | Laag |
Behandelingsmaatregelen
- Implement A.7.1 Physical security perimeter
- Implement A.7.2 Physical entry controls
- Implement A.7.3 Securing offices, rooms and facilities
- Implement A.7.4 Physical security monitoring
- Implement A.7.5 Protecting against physical and environmental threats
- Implement A.7.6 Working in secure areas
- Remind people to keep desks clean in Code of conduct (A.7.7 Clear desk and clear screen)
- Implement A.7.8 Equipment siting and protection
- Implement A.7.9 Security of assets off-premises
- Implement A.6.7 Remote working