2023-35 – External people have access to information (systems)
| Veld | Waarde |
|---|---|
| Status | Actief |
| Behandeling | Accepteren |
| Kans | Midden |
| Impact | Midden |
| Blootstelling | Midden |
| Restblootstelling | Laag |
| Eigenaar | Management |
| Verantwoordelijke | Security Officer |
Asset
Confidential information (systems)
Dreiging
External people, such as contractors, consultants or service personnel leak confidential information, due to: 1. No terms were agreed 2. No NDA was signed 3. Access is not timely removed
Risicocategorie
Vertrouwelijkheid, Integriteit
Risicoscore
| Kans | Impact | Blootstelling | Restblootstelling |
|---|---|---|---|
| Midden | Midden | Midden | Laag |
Behandelingsmaatregelen
- Limit the access of external accounts (A.5.15 Access control/ A.5.18 Access rights)
- Timely removal of external accounts A.5.16 Identity management)
- Sign NDA with external people (A.6.6 Confidentiality or non-disclosure agreements)
- Add NDA to contracts with suppliers (A.5.20 Addressing information security within supplier agreements)