Added YAML front matter to 27002-NL
This commit is contained in:
parent
92adf49834
commit
48f8fdb84b
93 changed files with 2320 additions and 0 deletions
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.1"
|
||||
title: "Beleidsregels voor informatiebeveiliging"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Governance]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Resilience
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.1 Beleidsregels voor informatiebeveiliging
|
||||
|
||||
| Attribuut | Waarde |
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.10"
|
||||
title: "Aanvaardbaar gebruik van informatie en andere gerelateerde bedrijfsmiddelen"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Asset_management
|
||||
- Information_protection
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.10 Aanvaardbaar gebruik van informatie en andere gerelateerde bedrijfsmiddelen
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.11"
|
||||
title: "Retourneren van bedrijfsmiddelen"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Asset_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.11 Retourneren van bedrijfsmiddelen
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.12"
|
||||
title: "Classificeren van informatie"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Information_protection]
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.12 Classificeren van informatie
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.13"
|
||||
title: "Labelen van informatie"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Information_protection]
|
||||
security_domains:
|
||||
- Defence
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.13 Labelen van informatie
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.14"
|
||||
title: "Overdragen van informatie"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Asset_management
|
||||
- Information_protection
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.14 Overdragen van informatie
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.15"
|
||||
title: "Toegangsbeveiliging"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Identity_and_access_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.15 Toegangsbeveiliging
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.16"
|
||||
title: "Identiteitsbeheer"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Identity_and_access_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.16 Identiteitsbeheer
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.17"
|
||||
title: "Beheren van authenticatie-informatie"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Identity_and_access_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.17 Beheren van authenticatie-informatie
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.18"
|
||||
title: "Toegangsrechten"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Identity_and_access_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.18 Toegangsrechten
|
||||
|
||||
| Attribuut | Waarde |
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.19"
|
||||
title: "Informatiebeveiliging in leveranciersrelaties"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Supplier_relationships_security]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.19 Informatiebeveiliging in leveranciersrelaties
|
||||
|
||||
| Attribuut | Waarde |
|
||||
|
|
|
|||
|
|
@ -1,3 +1,28 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.2"
|
||||
title: "Rollen en verantwoordelijkheden bij informatiebeveiliging"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Governance]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
- Resilience
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.2 Rollen en verantwoordelijkheden bij informatiebeveiliging
|
||||
|
||||
| Attribuut | Waarde |
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.20"
|
||||
title: "Adresseren van informatiebeveiliging in leveranciersovereenkomsten"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Supplier_relationships_security]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.20 Adresseren van informatiebeveiliging in leveranciersovereenkomsten
|
||||
|
||||
| Attribuut | Waarde |
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.21"
|
||||
title: "Beheren van informatiebeveiliging in de ICT-keten"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Supplier_relationships_security]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.21 Beheren van informatiebeveiliging in de ICT-keten
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.22"
|
||||
title: "Monitoren, beoordelen en het beheren van wijzigingen van leveranciersdiensten"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Supplier_relationships_security]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
- Defence
|
||||
- Information_security_assurance
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.22 Monitoren, beoordelen en het beheren van wijzigingen van leveranciersdiensten
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.23"
|
||||
title: "Informatiebeveiliging voor het gebruik van clouddiensten"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Supplier_relationships_security]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.23 Informatiebeveiliging voor het gebruik van clouddiensten
|
||||
|
||||
**Beheersmaatregel**
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.24"
|
||||
title: "Plannen en voorbereiden van het beheer van informatiebeveiligingsincidenten"
|
||||
theme: Organizational
|
||||
control_type: [Corrective]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Respond
|
||||
- Recover
|
||||
operational_capabilities:
|
||||
- Governance
|
||||
- Information_security_event_management
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.24 Plannen en voorbereiden van het beheer van informatiebeveiligingsincidenten
|
||||
|
||||
| Attribuut | Waarde |
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.25"
|
||||
title: "Beoordelen van en besluiten over informatiebeveiligingsgebeurtenissen"
|
||||
theme: Organizational
|
||||
control_type: [Detective]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Detect
|
||||
- Respond
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.25 Beoordelen van en besluiten over informatiebeveiligingsgebeurtenissen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.26"
|
||||
title: "Reageren op informatiebeveiligingsincidenten"
|
||||
theme: Organizational
|
||||
control_type: [Corrective]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Respond
|
||||
- Recover
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.26 Reageren op informatiebeveiligingsincidenten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.27"
|
||||
title: "Leren van informatiebeveiligingsincidenten"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.27 Leren van informatiebeveiligingsincidenten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.28"
|
||||
title: "Verzamelen van bewijsmateriaal"
|
||||
theme: Organizational
|
||||
control_type: [Corrective]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Detect
|
||||
- Respond
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.28 Verzamelen van bewijsmateriaal
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,31 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.29"
|
||||
title: "Informatiebeveiliging tijdens een verstoring"
|
||||
theme: Organizational
|
||||
control_type:
|
||||
- Preventive
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Respond
|
||||
operational_capabilities: [Continuity]
|
||||
security_domains:
|
||||
- Protection
|
||||
- Resilience
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.29 Informatiebeveiliging tijdens een verstoring
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.3"
|
||||
title: "Functiescheiding"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Governance
|
||||
- Identity_and_access_management
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.3 Functiescheiding
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,22 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.30"
|
||||
title: "ICT-gereedheid voor bedrijfscontinuïteit"
|
||||
theme: Organizational
|
||||
control_type: [Corrective]
|
||||
information_security_properties: [Availability]
|
||||
cybersecurity_concepts: [Respond]
|
||||
operational_capabilities: [Continuity]
|
||||
security_domains: [Resilience]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.30 ICT-gereedheid voor bedrijfscontinuïteit
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.31"
|
||||
title: "Wettelijke, statutaire, regelgevende en contractuele eisen"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Legal_and_compliance]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.31 Wettelijke, statutaire, regelgevende en contractuele eisen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+------------------------------+--------------------------------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.32"
|
||||
title: "Intellectuele-eigendomsrechten"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Legal_and_compliance]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.32 Intellectuele-eigendomsrechten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,30 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.33"
|
||||
title: "Beschermen van registraties"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
operational_capabilities:
|
||||
- Legal_and_compliance
|
||||
- Asset_management
|
||||
- Information_protection
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.33 Beschermen van registraties
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.34"
|
||||
title: "Privacy en bescherming van persoonsgegevens"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
operational_capabilities:
|
||||
- Information_protection
|
||||
- Legal_and_compliance
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.34 Privacy en bescherming van persoonsgegevens
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.35"
|
||||
title: "Onafhankelijke beoordeling van informatiebeveiliging"
|
||||
theme: Organizational
|
||||
control_type:
|
||||
- Preventive
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
operational_capabilities: [Information_security_assurance]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.35 Onafhankelijke beoordeling van informatiebeveiliging
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.36"
|
||||
title: "Naleving van beleid, regels en normen voor informatiebeveiliging"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
operational_capabilities:
|
||||
- Legal_and_compliance
|
||||
- Information_security_assurance
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.36 Naleving van beleid, regels en normen voor informatiebeveiliging
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,41 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.37"
|
||||
title: "Gedocumenteerde bedieningsprocedures"
|
||||
theme: Organizational
|
||||
control_type:
|
||||
- Preventive
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Recover
|
||||
operational_capabilities:
|
||||
- Asset_management
|
||||
- Physical_security
|
||||
- System_and_network_security
|
||||
- Application_security
|
||||
- Secure_configuration
|
||||
- Identity_and_access_management
|
||||
- Threat_and_vulnerability_management
|
||||
- Continuity
|
||||
- Information_security_event_management
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.37 Gedocumenteerde bedieningsprocedures
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+---------------------------------------------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.4"
|
||||
title: "Managementverantwoordelijkheden"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Governance]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.4 Managementverantwoordelijkheden
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,33 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.5"
|
||||
title: "Contact met overheidsinstanties"
|
||||
theme: Organizational
|
||||
control_type:
|
||||
- Preventive
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
- Respond
|
||||
- Recover
|
||||
operational_capabilities: [Governance]
|
||||
security_domains:
|
||||
- Defence
|
||||
- Resilience
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.5 Contact met overheidsinstanties
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,30 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.6"
|
||||
title: "Contact met speciale belangengroepen"
|
||||
theme: Organizational
|
||||
control_type:
|
||||
- Preventive
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Respond
|
||||
- Recover
|
||||
operational_capabilities: [Governance]
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.6 Contact met speciale belangengroepen
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,33 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.7"
|
||||
title: "Informatie en analyses over dreigingen"
|
||||
theme: Organizational
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Detect
|
||||
- Respond
|
||||
operational_capabilities: [Threat_and_vulnerability_management]
|
||||
security_domains:
|
||||
- Defence
|
||||
- Resilience
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.7 Informatie en analyses over dreigingen
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.8"
|
||||
title: "Informatiebeveiliging in projectmanagement"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
operational_capabilities: [Governance]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.8 Informatiebeveiliging in projectmanagement
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "5.9"
|
||||
title: "Inventarisatie van informatie en andere gerelateerde bedrijfsmiddelen"
|
||||
theme: Organizational
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities: [Asset_management]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 5.9 Inventarisatie van informatie en andere gerelateerde bedrijfsmiddelen
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,47 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.1"
|
||||
title: "Screening"
|
||||
theme: People
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Human_resource_security]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.1"
|
||||
title: "Screening"
|
||||
theme: People
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Human_resource_security]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.1 Screening
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.2"
|
||||
title: "Arbeidsovereenkomst"
|
||||
theme: People
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Human_resource_security]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.2 Arbeidsovereenkomst
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.3"
|
||||
title: "Bewustwording van, opleiding en training in informatiebeveiliging"
|
||||
theme: People
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Human_resource_security]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.3 Bewustwording van, opleiding en training in informatiebeveiliging
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.4"
|
||||
title: "Disciplinaire procedure"
|
||||
theme: People
|
||||
control_type:
|
||||
- Preventive
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Respond
|
||||
operational_capabilities: [Human_resource_security]
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.4 Disciplinaire procedure
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.5"
|
||||
title: "Verantwoordelijkheden na beëindiging of wijziging van het dienstverband"
|
||||
theme: People
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Human_resource_security
|
||||
- Asset_management
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.5 Verantwoordelijkheden na beëindiging of wijziging van het dienstverband
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-----------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.6"
|
||||
title: "Vertrouwelijkheids- of geheimhoudingsovereenkomsten"
|
||||
theme: People
|
||||
control_type: [Preventive]
|
||||
information_security_properties: [Confidentiality]
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Human_resource_security
|
||||
- Information_protection
|
||||
- Supplier_relationships_security
|
||||
security_domains: [Governance_and_Ecosystem]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.6 Vertrouwelijkheids- of geheimhoudingsovereenkomsten
|
||||
|
||||
+------------------------+----------------------+----------------------+-----------------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.7"
|
||||
title: "Werken op afstand"
|
||||
theme: People
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Asset_management
|
||||
- Information_protection
|
||||
- Physical_security
|
||||
- System_and_network_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.7 Werken op afstand
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "6.8"
|
||||
title: "Melden van informatiebeveiligingsgebeurtenissen"
|
||||
theme: People
|
||||
control_type: [Detective]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Detect]
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 6.8 Melden van informatiebeveiligingsgebeurtenissen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.1"
|
||||
title: "Fysieke beveiligingszones"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Physical_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.1 Fysieke beveiligingszones
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.10"
|
||||
title: "Opslagmedia"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Physical_security
|
||||
- Asset_management
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.10 Opslagmedia
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,28 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.11"
|
||||
title: "Nutsvoorzieningen"
|
||||
theme: Physical
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
information_security_properties:
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities: [Physical_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.11 Nutsvoorzieningen
|
||||
|
||||
+------------------------+---------------------+----------------------+------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,24 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.12"
|
||||
title: "Beveiligen van bekabeling"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Physical_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.12 Beveiligen van bekabeling
|
||||
|
||||
+------------------------+----------------------+----------------------+------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.13"
|
||||
title: "Onderhoud van apparatuur"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Physical_security
|
||||
- Asset_management
|
||||
security_domains:
|
||||
- Protection
|
||||
- Resilience
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.13 Onderhoud van apparatuur
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,24 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.14"
|
||||
title: "Veilig verwijderen of hergebruiken van apparatuur"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties: [Confidentiality]
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Physical_security
|
||||
- Asset_management
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.14 Veilig verwijderen of hergebruiken van apparatuur
|
||||
|
||||
+------------------------+----------------------+----------------------+-------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.2"
|
||||
title: "Fysieke toegangsbeveiliging"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Physical_security
|
||||
- Identity_and_access_management
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.2 Fysieke toegangsbeveiliging
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.3"
|
||||
title: "Beveiligen van kantoren, ruimten en faciliteiten"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Physical_security
|
||||
- Asset_management
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.3 Beveiligen van kantoren, ruimten en faciliteiten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,31 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.4"
|
||||
title: "Monitoren van de fysieke beveiliging"
|
||||
theme: Physical
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities: [Physical_security]
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.4 Monitoren van de fysieke beveiliging
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.5"
|
||||
title: "Beschermen tegen fysieke en omgevingsdreigingen"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Physical_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.5 Beschermen tegen fysieke en omgevingsdreigingen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.6"
|
||||
title: "Werken in beveiligde zones"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Physical_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.6 Werken in beveiligde zones
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,22 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.7"
|
||||
title: "‘Clear desk’ en ‘clear screen’"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties: [Confidentiality]
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Physical_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.7 ‘Clear desk’ en ‘clear screen’
|
||||
|
||||
+------------------------+----------------------+----------------------+------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.8"
|
||||
title: "Plaatsen en beschermen van apparatuur"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Physical_security
|
||||
- Asset_management
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.8 Plaatsen en beschermen van apparatuur
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "7.9"
|
||||
title: "Beveiligen van bedrijfsmiddelen buiten het terrein"
|
||||
theme: Physical
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Physical_security
|
||||
- Asset_management
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 7.9 Beveiligen van bedrijfsmiddelen buiten het terrein
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,51 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.1"
|
||||
title: "‘User endpoint devices’"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Asset_management
|
||||
- Information_protection
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.1"
|
||||
title: "‘User endpoint devices’"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Asset_management
|
||||
- Information_protection
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.1 ‘User endpoint devices’
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,3 +1,24 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.10"
|
||||
title: "Wissen van informatie"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties: [Confidentiality]
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Information_protection
|
||||
- Legal_and_compliance
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.10 Wissen van informatie
|
||||
|
||||
+------------------------+----------------------+----------------------+-------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,22 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.11"
|
||||
title: "Maskeren van gegevens"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties: [Confidentiality]
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Information_protection]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.11 Maskeren van gegevens
|
||||
|
||||
+------------------------+----------------------+----------------------+--------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,28 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.12"
|
||||
title: "Voorkomen van gegevenslekken (Data leakage prevention)"
|
||||
theme: Technological
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
information_security_properties: [Confidentiality]
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities: [Information_protection]
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.12 Voorkomen van gegevenslekken (Data leakage prevention)
|
||||
|
||||
+------------------------+----------------------+----------------------+----------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,24 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.13"
|
||||
title: "Back-up van informatie"
|
||||
theme: Technological
|
||||
control_type: [Corrective]
|
||||
information_security_properties:
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Recover]
|
||||
operational_capabilities: [Continuity]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.13 Back-up van informatie
|
||||
|
||||
+------------------------+---------------------+----------------------+--------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,26 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.14"
|
||||
title: "Redundantie van informatieverwerkende faciliteiten"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties: [Availability]
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Continuity
|
||||
- Asset_management
|
||||
security_domains:
|
||||
- Protection
|
||||
- Resilience
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.14 Redundantie van informatieverwerkende faciliteiten
|
||||
|
||||
+------------------------+---------------------+----------------------+------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,51 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.15"
|
||||
title: "Logging"
|
||||
theme: Technological
|
||||
control_type: [Detective]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Detect]
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.15"
|
||||
title: "Logging"
|
||||
theme: Technological
|
||||
control_type: [Detective]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Detect]
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.15 Logging
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.16"
|
||||
title: "Monitoren van activiteiten"
|
||||
theme: Technological
|
||||
control_type:
|
||||
- Detective
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Detect
|
||||
- Respond
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains: [Defence]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.16 Monitoren van activiteiten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,26 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.17"
|
||||
title: "Kloksynchronisatie"
|
||||
theme: Technological
|
||||
control_type: [Detective]
|
||||
information_security_properties: [Integrity]
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities: [Information_security_event_management]
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.17 Kloksynchronisatie
|
||||
|
||||
+------------------------+---------------------+----------------------+--------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,28 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.18"
|
||||
title: "Gebruik van speciale systeemhulpmiddelen"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- System_and_network_security
|
||||
- Secure_configuration
|
||||
- Application_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.18 Gebruik van speciale systeemhulpmiddelen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+---------------------------------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.19"
|
||||
title: "Installeren van software op operationele systemen"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Secure_configuration
|
||||
- Application_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.19 Installeren van software op operationele systemen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+---------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.2"
|
||||
title: "Speciale toegangsrechten"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Identity_and_access_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.2 Speciale toegangsrechten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.20"
|
||||
title: "Beveiliging netwerkcomponenten"
|
||||
theme: Technological
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities: [System_and_network_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.20 Beveiliging netwerkcomponenten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+---------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.21"
|
||||
title: "Beveiliging van netwerkdiensten"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [System_and_network_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.21 Beveiliging van netwerkdiensten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.22"
|
||||
title: "Netwerksegmentatie"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [System_and_network_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.22 Netwerksegmentatie
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.23"
|
||||
title: "Toepassen van webfilters"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [System_and_network_security]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.23 Toepassen van webfilters
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+--------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.24"
|
||||
title: "Gebruik van cryptografie"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Secure_configuration]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.24 Gebruik van cryptografie
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.25"
|
||||
title: "Beveiligen tijdens de ontwikkelcyclus"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Application_security
|
||||
- System_and_network_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.25 Beveiligen tijdens de ontwikkelcyclus
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.26"
|
||||
title: "Toepassingsbeveiligingseisen"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Application_security
|
||||
- System_and_network_security
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.26 Toepassingsbeveiligingseisen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.27"
|
||||
title: "Veilige systeemarchitectuur en technische uitgangspunten"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Application_security
|
||||
- System_and_network_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.27 Veilige systeemarchitectuur en technische uitgangspunten
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.28"
|
||||
title: "Veilig coderen"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Application_security
|
||||
- System_and_network_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.28 Veilig coderen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,28 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.29"
|
||||
title: "Testen van de beveiliging tijdens ontwikkeling en acceptatie"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Identify]
|
||||
operational_capabilities:
|
||||
- Application_security
|
||||
- Information_security_assurance
|
||||
- System_and_network_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.29 Testen van de beveiliging tijdens ontwikkeling en acceptatie
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-----------------------------------------------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.3"
|
||||
title: "Beperking toegang tot informatie"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Identity_and_access_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.3 Beperking toegang tot informatie
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,35 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.30"
|
||||
title: "Uitbestede systeemontwikkeling"
|
||||
theme: Technological
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities:
|
||||
- System_and_network_security
|
||||
- Application_security
|
||||
- Supplier_relationships_security
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.30 Uitbestede systeemontwikkeling
|
||||
|
||||
+------------------------+----------------------------------------------------+------------------------------------------+-----------------------------------------------------------------------------------------------------+--------------------------------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.31"
|
||||
title: "Scheiding van ontwikkel-, test- en productieomgevingen"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Application_security
|
||||
- System_and_network_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.31 Scheiding van ontwikkel-, test- en productieomgevingen
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,27 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.32"
|
||||
title: "Wijzigingsbeheer"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Application_security
|
||||
- System_and_network_security
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.32 Wijzigingsbeheer
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,24 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.33"
|
||||
title: "Testgegevens"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Information_protection]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.33 Testgegevens
|
||||
|
||||
+------------------------+----------------------+----------------------+--------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,29 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.34"
|
||||
title: "Bescherming van informatiesystemen tijdens audits"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- System_and_network_security
|
||||
- Information_protection
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.34 Bescherming van informatiesystemen tijdens audits
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------------+--------------------------------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,28 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.4"
|
||||
title: "Toegangsbeveiliging op broncode"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities:
|
||||
- Identity_and_access_management
|
||||
- Application_security
|
||||
- Secure_configuration
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.4 Toegangsbeveiliging op broncode
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.5"
|
||||
title: "Beveiligde authenticatie"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Identity_and_access_management]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.5 Beveiligde authenticatie
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,31 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.6"
|
||||
title: "Capaciteitsbeheer"
|
||||
theme: Technological
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
information_security_properties:
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities: [Continuity]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.6 Capaciteitsbeheer
|
||||
|
||||
+------------------------+---------------------+------------------------------------------+--------------------+--------------------------------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,34 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.7"
|
||||
title: "Bescherming tegen malware"
|
||||
theme: Technological
|
||||
control_type:
|
||||
- Preventive
|
||||
- Detective
|
||||
- Corrective
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Protect
|
||||
- Detect
|
||||
operational_capabilities:
|
||||
- System_and_network_security
|
||||
- Information_protection
|
||||
security_domains:
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.7 Bescherming tegen malware
|
||||
|
||||
+---------------------------------------+----------------------------------------------------+----------------------+----------------------------------------------------------------+---------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,30 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.8"
|
||||
title: "Beheer van technische kwetsbaarheden"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts:
|
||||
- Identify
|
||||
- Protect
|
||||
operational_capabilities: [Threat_and_vulnerability_management]
|
||||
security_domains:
|
||||
- Governance_and_Ecosystem
|
||||
- Protection
|
||||
- Defence
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.8 Beheer van technische kwetsbaarheden
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+------------------------------------------------+-----------------------------+
|
||||
|
|
|
|||
|
|
@ -1,3 +1,25 @@
|
|||
---
|
||||
notetype: sourcetext
|
||||
standard: ISO 27002
|
||||
version: 2022
|
||||
language: NL
|
||||
type: control
|
||||
id: "8.9"
|
||||
title: "Configuratiebeheer"
|
||||
theme: Technological
|
||||
control_type: [Preventive]
|
||||
information_security_properties:
|
||||
- Confidentiality
|
||||
- Integrity
|
||||
- Availability
|
||||
cybersecurity_concepts: [Protect]
|
||||
operational_capabilities: [Secure_configuration]
|
||||
security_domains: [Protection]
|
||||
tags:
|
||||
- iso27002/2022/NL
|
||||
- iso27002/2022/EN
|
||||
status: active
|
||||
---
|
||||
## 8.9 Configuratiebeheer
|
||||
|
||||
+------------------------+----------------------------------------------------+----------------------+-------------------------+---------------------+
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue