Ga naar inhoud

2023-35 – External people have access to information (systems)

Veld Waarde
Status Actief
Behandeling Accepteren
Kans Midden
Impact Midden
Blootstelling Midden
Restblootstelling Laag
Eigenaar Management
Verantwoordelijke Security Officer

Asset

Confidential information (systems)

Dreiging

External people, such as contractors, consultants or service personnel leak confidential information, due to: 1. No terms were agreed 2. No NDA was signed 3. Access is not timely removed

Risicocategorie

Vertrouwelijkheid, Integriteit

Risicoscore

Kans Impact Blootstelling Restblootstelling
Midden Midden Midden Laag

Behandelingsmaatregelen

  • Limit the access of external accounts (A.5.15 Access control/ A.5.18 Access rights)
  • Timely removal of external accounts A.5.16 Identity management)
  • Sign NDA with external people (A.6.6 Confidentiality or non-disclosure agreements)
  • Add NDA to contracts with suppliers (A.5.20 Addressing information security within supplier agreements)

Gerelateerde documenten