removed emoji from filenames, Obsidian changed all relevant links
This commit is contained in:
parent
d316285a74
commit
68f1c38681
638 changed files with 710 additions and 3176 deletions
|
|
@ -22,7 +22,7 @@
|
|||
- m400s040: [[iso27diy-m300s510|m300s510]]: **SWOT analysis** ([C4.1](../Corpus/Standards/MoCs/ISO_27001_2022_4.1_MoC%20Understanding%20the%20organization%20and%20its%20context.md))
|
||||
- m400s050: Stakeholder Analysis ([C4.2](../Corpus/Standards/MoCs/ISO_27001_2022_4.2_MoC%20Understanding%20the%20needs%20and%20expectations%20of%20interested%20parties.md))
|
||||
- **m410:Organizational Structures**
|
||||
- [Introduction for Organizational Structures](../Corpus/🎇%20Sparks/Introduction%20for%20Organizational%20Structures.md)
|
||||
- [Introduction for Organizational Structures](../Corpus/Sparks/Introduction%20for%20Organizational%20Structures.md)
|
||||
- Organizational processes ([C4.1](../Corpus/Standards/MoCs/ISO_27001_2022_4.1_MoC%20Understanding%20the%20organization%20and%20its%20context.md))
|
||||
- Organization Chart ([C4.1](../Corpus/Standards/MoCs/ISO_27001_2022_4.1_MoC%20Understanding%20the%20organization%20and%20its%20context.md))
|
||||
- Job architecture ([C4.1](../Corpus/Standards/MoCs/ISO_27001_2022_4.1_MoC%20Understanding%20the%20organization%20and%20its%20context.md))
|
||||
|
|
|
|||
|
|
@ -22,7 +22,7 @@ Examples:
|
|||
4. develop interventions based on these differences
|
||||
|
||||
**Threat analysis**
|
||||
- do a threat analysis, see [Create a threat analysis chatbot](../../Corpus/💡Drafts%20and%20Ideas/Controls/Create%20a%20threat%20analysis%20chatbot.md)
|
||||
- do a threat analysis, see [Create a threat analysis chatbot](../../Corpus/Drafts%20and%20Ideas/Controls/Create%20a%20threat%20analysis%20chatbot.md)
|
||||
|
||||
|
||||
**Policy drafting**
|
||||
|
|
|
|||
|
|
@ -429,7 +429,7 @@
|
|||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{"id":"6c394a4088d586b3","type":"file","file":"iso27diy-corp/Corpus/📎 Attachments/Canvas Cyclus.png","x":382,"y":620,"width":278,"height":200},
|
||||
{"id":"6c394a4088d586b3","type":"file","file":"iso27diy-corp/Corpus/Attachments/Canvas Cyclus.png","x":382,"y":620,"width":278,"height":200},
|
||||
{
|
||||
"id":"1e6b25bf6dcb833e",
|
||||
"type":"text",
|
||||
|
|
@ -470,8 +470,8 @@
|
|||
"width":1068,
|
||||
"height":60
|
||||
},
|
||||
{"id":"ddfc9917c2c7fc66","type":"file","file":"iso27diy-corp/Corpus/📎 Attachments/Canvas Cyclus.png","x":-408,"y":620,"width":278,"height":200},
|
||||
{"id":"27d02011ccccb4c0","type":"file","file":"iso27diy-corp/Corpus/📎 Attachments/Canvas Cyclus.png","x":-19,"y":620,"width":278,"height":200}
|
||||
{"id":"ddfc9917c2c7fc66","type":"file","file":"iso27diy-corp/Corpus/Attachments/Canvas Cyclus.png","x":-408,"y":620,"width":278,"height":200},
|
||||
{"id":"27d02011ccccb4c0","type":"file","file":"iso27diy-corp/Corpus/Attachments/Canvas Cyclus.png","x":-19,"y":620,"width":278,"height":200}
|
||||
],
|
||||
"edges":[],
|
||||
"metadata":{
|
||||
|
|
|
|||
|
|
@ -10,7 +10,7 @@ Gebaseerd op:
|
|||
|
||||
Resultaten:
|
||||
- [BIA resultaat in MIRO](BIA%20resultaat%20MIRO.pdf)
|
||||
- [Maximum Down Time systemen per proces](../../Corpus/📎%20Attachments/BIA%20resultaten.numbers)
|
||||
- [Maximum Down Time systemen per proces](../../Corpus/Attachments/BIA%20resultaten.numbers)
|
||||
- [Rapportage in Word](250128%20Business%20Impact%20Analyse%20DAK.docx)
|
||||
|
||||
## Deelnemers
|
||||
|
|
@ -35,7 +35,7 @@ Voorstelrondje (voor deelnemers die er in de vorige workshop ([BIA](BIA%20Worksh
|
|||
|
||||
In de workshop van vorige week hebben we gekeken hoe lang systemen gemist konden worden, voordat de verschillende bedrijfsprocessen hiervan schade ondervonden (en het dus meer werd dan 'erg onhandig').
|
||||
|
||||
Daarvan wil ik de resultaten nu met jullie delen: [Maximum Down Time systemen per proces](../../Corpus/📎%20Attachments/BIA%20resultaten.numbers).
|
||||
Daarvan wil ik de resultaten nu met jullie delen: [Maximum Down Time systemen per proces](../../Corpus/Attachments/BIA%20resultaten.numbers).
|
||||
|
||||
In deze sessie gaan we voor de kwetsbaarste processen kijken welke noodmaatregelen we kunnen inzetten als de meest kritische systemen uitvallen, hoe we die noodmaatregelen kunnen voorbereiden, wie we daarvoor nodig hebben, en hoe we gaan communiceren met de verschillende stakeholders over die noodmaatregelen.
|
||||
|
||||
|
|
@ -51,7 +51,7 @@ Kwetsbaarheden gescoord volgens het Common Vulnerability Scoring System ([CVSS v
|
|||
Voor het gebruik van de SA_VEEAM backup software is een Domain Administrator account aangemaakt. Dit geeft directe toegang geeft tot de volledige Active Directory-omgeving. Een aanvaller kan hiermee back-ups manipuleren, verwijderen of zelfs de volledige Active Directory overnemen. Het principe van least privilege lijkt niet te zijn toegepast
|
||||
|
||||
Volgens Vitaen is dit 'in de meeste gevallen niet noodzakelijk en verhoogt het aanvalsoppervlak aanzienlijk':
|
||||
>Aangezien dit account vatbaar is voor een [Kerberoasting](../../Corpus/🎇%20Sparks/Kerberoasting.md) aanval, is het mogelijk gebleken de wachtwoord hash te bemachtigen. Het bleek echter niet mogelijk in de korte tijd dat de opdracht plaatsvond, om hiervan het wachtwoord te brute-forcen.
|
||||
>Aangezien dit account vatbaar is voor een [Kerberoasting](../../Corpus/Sparks/Kerberoasting.md) aanval, is het mogelijk gebleken de wachtwoord hash te bemachtigen. Het bleek echter niet mogelijk in de korte tijd dat de opdracht plaatsvond, om hiervan het wachtwoord te brute-forcen.
|
||||
|
||||
**Oplossingsrichting**
|
||||
> Vitaen adviseert om het principe van least privilege toe te passen: service accounts mogen alleen de rechten krijgen die strikt noodzakelijk zijn voor hun functionaliteit. Waar mogelijk moeten alternatieve oplossingen zoals Managed Service Accounts (MSA) of Group Managed Service Accounts (gMSA) worden gebruikt, die automatisch wachtwoorden roteren en minder risicovol zijn. Daarnaast moet het gebruik van service accounts met verhoogde rechten actief worden gemonitord en gelogd, zodat afwijkend gedrag direct wordt opgemerkt.
|
||||
471
Clients/Gastenhuis/Gastenhuis Projectaanpak.canvas
Normal file
471
Clients/Gastenhuis/Gastenhuis Projectaanpak.canvas
Normal file
|
|
@ -0,0 +1,471 @@
|
|||
{
|
||||
"nodes":[
|
||||
{"id":"09f6d6c1e8efb6e6","type":"group","x":-460,"y":1080,"width":1160,"height":620,"label":"Beleid voor Uitvoering (H8)"},
|
||||
{"id":"7a48b34c6273cdae","type":"group","x":-460,"y":-580,"width":1160,"height":540,"label":"Context, Strategie en Leiderschap (H4, H5)"},
|
||||
{"id":"6110ac3efe0e4494","type":"group","x":-460,"y":560,"width":1160,"height":400,"label":"PDCA voor Risicomanagement met de Canvas Methode (H8.2, H8.3)"},
|
||||
{"id":"07178dd4253722ab","type":"group","x":-460,"y":80,"width":1160,"height":360,"label":"Risico's en Maatregelen (H6)"},
|
||||
{"id":"288cd10d35aa383a","type":"group","x":300,"y":1800,"width":400,"height":360,"label":"Evaluatie en Verbetering (H9, H10)"},
|
||||
{"id":"1520dd2bd87611ec","type":"group","x":-80,"y":1800,"width":339,"height":360,"label":"Documentatie (H7.5)"},
|
||||
{"id":"1cd9769688fd69c3","type":"group","x":-460,"y":1800,"width":330,"height":360,"label":"Ondersteuning (H7.1-4)"},
|
||||
{
|
||||
"id":"82679ef2d10465f6",
|
||||
"type":"text",
|
||||
"text":"Asset Inventarisatie (A5.9)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":110,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"90146875843a9610",
|
||||
"type":"text",
|
||||
"text":"Dataclassificatie (A5.12)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":220,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"f967f99a6d088039",
|
||||
"type":"text",
|
||||
"text":"Rollen en Verantw.heden (A5.2-5.4)",
|
||||
"styleAttributes":{},
|
||||
"x":-50,
|
||||
"y":330,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"53437152acfbfaa1",
|
||||
"type":"text",
|
||||
"text":"Planning Maatregelen (H8.1)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":330,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"4c92dc5b2f76a9a5",
|
||||
"type":"text",
|
||||
"text":"Risicoinventarisatie (H6.1.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-50,
|
||||
"y":110,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"4db47e26ac77f040",
|
||||
"type":"text",
|
||||
"text":"Penetratie test (A5.35, A8.8)",
|
||||
"styleAttributes":{
|
||||
"textAlign":null
|
||||
},
|
||||
"x":-420,
|
||||
"y":220,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"872cfd9071333367",
|
||||
"type":"text",
|
||||
"text":"Risicoanalyse (H6.1.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-50,
|
||||
"y":220,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"40e49243a6b68dcb",
|
||||
"type":"text",
|
||||
"text":"Identificeren Maatregelen (H6.1.3)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":330,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"464dfc9a3def80c2",
|
||||
"type":"text",
|
||||
"text":"Dreigingsanalyse (A5.7)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":110,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"41e3b0bc38d8de84",
|
||||
"type":"text",
|
||||
"text":"SWOT analyse (H4.1)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":-340,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"763fb2036c5dbdde",
|
||||
"type":"text",
|
||||
"text":"DESTEP analyse (H4.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-50,
|
||||
"y":-340,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"c8f64dbe95f776d2",
|
||||
"type":"text",
|
||||
"text":"Planning ISMS (H6.1.1)",
|
||||
"styleAttributes":{"textAlign":"center"},
|
||||
"x":-420,
|
||||
"y":-140,
|
||||
"width":1080,
|
||||
"height":60
|
||||
},
|
||||
{
|
||||
"id":"047bf657e7c0381f",
|
||||
"type":"text",
|
||||
"text":"Functiehuis (H4.1)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":-240,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"a3402198a7fa4e49",
|
||||
"type":"text",
|
||||
"text":"Bedrijfsprocessen (H4.1)",
|
||||
"styleAttributes":{},
|
||||
"x":-50,
|
||||
"y":-240,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"0b7306dec1c85f8d",
|
||||
"type":"text",
|
||||
"text":"Stakeholder analyse (H4.2)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":-340,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"4d7c1e2e9e3b5995",
|
||||
"type":"text",
|
||||
"text":"Wet- en Regelgeving\n(H4.2, A5.31-34)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":-240,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"39689fc26569c699",
|
||||
"type":"text",
|
||||
"text":"Besturingsmodel (H4.1)",
|
||||
"styleAttributes":{},
|
||||
"x":-50,
|
||||
"y":-440,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"a36ad925134021b2",
|
||||
"type":"text",
|
||||
"text":"Management Workshop\n(H7.3, A6.3, A6.9)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":-440,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"2706559829c7a060",
|
||||
"type":"text",
|
||||
"text":"Risicobereidheid (H6.1.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":-440,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"1f0798149501d740",
|
||||
"type":"text",
|
||||
"text":"Bepalen Doelstellingen (H6.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":-540,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"f0b8fe39fe16ba4e",
|
||||
"type":"text",
|
||||
"text":"Bepalen Scope (H4.3)",
|
||||
"styleAttributes":{},
|
||||
"x":-50,
|
||||
"y":-540,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"6a322f5cf5bd3f6a",
|
||||
"type":"text",
|
||||
"text":"Informatiebeveiligingsbeleid (H5.2)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":-540,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"549f8f6976e2591a",
|
||||
"type":"text",
|
||||
"text":"Documentatie (H7.5.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-60,
|
||||
"y":1840,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"a2d22052ff7096c5",
|
||||
"type":"text",
|
||||
"text":"Review kalender (H7.5.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-60,
|
||||
"y":1940,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"0968542472225677",
|
||||
"type":"text",
|
||||
"text":"Communicatieplan (H7.4)",
|
||||
"styleAttributes":{},
|
||||
"x":-60,
|
||||
"y":2040,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"273d40cfef57c393",
|
||||
"type":"text",
|
||||
"text":"Audits en Reviews (H9.2, A.5.35-36)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":1840,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"28b11a96eef5c2b0",
|
||||
"type":"text",
|
||||
"text":"Management Review (H9.3)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":1940,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"0a5dc3ad69ffafc2",
|
||||
"type":"text",
|
||||
"text":"Beschikbaarstellen Middelen (H7.1)",
|
||||
"styleAttributes":{},
|
||||
"x":-440,
|
||||
"y":1840,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"1e34a0d420b8cfcd",
|
||||
"type":"text",
|
||||
"text":"Competenties (H7.2)",
|
||||
"styleAttributes":{},
|
||||
"x":-440,
|
||||
"y":1940,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"13dcb395f4d8f739",
|
||||
"type":"text",
|
||||
"text":"Afwijkingen en Correcties (H10.1)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":2040,
|
||||
"width":280,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"d5be08d2d1baa414",
|
||||
"type":"text",
|
||||
"text":"Toegangsbeleid\n(A5.15-18, A8.2-5)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":1344,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"314b04a8959f6fb5",
|
||||
"type":"text",
|
||||
"text":"Device management\n(A7.9-7.10, A8.1, 8.7)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":1445,
|
||||
"width":340,
|
||||
"height":90
|
||||
},
|
||||
{
|
||||
"id":"572c91765b41f7f3",
|
||||
"type":"text",
|
||||
"text":"Selectie en implementatie van technologie (A5.8, A5.23, A8.26-33, A.5.38-39, A7.13-14)",
|
||||
"styleAttributes":{},
|
||||
"x":-40,
|
||||
"y":1344,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"79a0be9c6f598831",
|
||||
"type":"text",
|
||||
"text":"Leveranciersmanagement (A5.19-A5.23, A8.29)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":1344,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"68a6efa1a776c676",
|
||||
"type":"text",
|
||||
"text":"Fysieke beveiliging\n(A7.1-7.8, 7.12)",
|
||||
"styleAttributes":{},
|
||||
"x":-40,
|
||||
"y":1445,
|
||||
"width":340,
|
||||
"height":90
|
||||
},
|
||||
{
|
||||
"id":"d3b8c88bc841e209",
|
||||
"type":"text",
|
||||
"text":"Business Impact Analyse (A5.29-5.30)",
|
||||
"styleAttributes":{},
|
||||
"x":-40,
|
||||
"y":1120,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"853301ab7242b5ef",
|
||||
"type":"text",
|
||||
"text":"Gebruikersbeleid\n(A5.10-14, A5.37, A5.40, A6.7-6.8, A7.7, A8.24)",
|
||||
"styleAttributes":{},
|
||||
"x":-40,
|
||||
"y":1235,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"1e6b25bf6dcb833e",
|
||||
"type":"text",
|
||||
"text":"Bedrijfscontinuïteitsplan (A5.29-5.30, A5.42, A7.11)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":1120,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"94c365431ffd100e",
|
||||
"type":"text",
|
||||
"text":"Bewustzijn en training\n(H7.3, A6.3)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":1235,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"eaa3c32d191b350e",
|
||||
"type":"text",
|
||||
"text":"Personeelsbeleid\n(A6.1-6.6)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":1235,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"4184e9e168fd5fdf",
|
||||
"type":"text",
|
||||
"text":"Beleid overige maatregelen (A5.1)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":1565,
|
||||
"width":340,
|
||||
"height":90
|
||||
},
|
||||
{
|
||||
"id":"6273a5aafc2f54d2",
|
||||
"type":"text",
|
||||
"text":"ICT Beheer (A8.7-8.35)",
|
||||
"styleAttributes":{},
|
||||
"x":320,
|
||||
"y":1445,
|
||||
"width":340,
|
||||
"height":90
|
||||
},
|
||||
{
|
||||
"id":"360024c970e70d34",
|
||||
"type":"text",
|
||||
"text":"Implementatie maatregelen (H8.3)",
|
||||
"styleAttributes":{"textAlign":"center"},
|
||||
"x":-40,
|
||||
"y":1565,
|
||||
"width":700,
|
||||
"height":90
|
||||
},
|
||||
{
|
||||
"id":"ff8f4d59b9462109",
|
||||
"type":"text",
|
||||
"text":"Incidentenbeheer \n(A5.24-29, A5.43, A6.8)",
|
||||
"styleAttributes":{},
|
||||
"x":-420,
|
||||
"y":1120,
|
||||
"width":340,
|
||||
"height":80
|
||||
},
|
||||
{
|
||||
"id":"8cf31932e32c4d1c",
|
||||
"type":"text",
|
||||
"text":"Continue verbetering (H10.1)",
|
||||
"styleAttributes":{"textAlign":"center"},
|
||||
"x":-408,
|
||||
"y":880,
|
||||
"width":1068,
|
||||
"height":60
|
||||
},
|
||||
{"id":"ddfc9917c2c7fc66","type":"file","file":"iso27diy-corp/Corpus/Attachments/Canvas Cyclus.png","x":-408,"y":620,"width":278,"height":200},
|
||||
{"id":"27d02011ccccb4c0","type":"file","file":"iso27diy-corp/Corpus/Attachments/Canvas Cyclus.png","x":-19,"y":620,"width":278,"height":200},
|
||||
{"id":"6c394a4088d586b3","type":"file","file":"iso27diy-corp/Corpus/Attachments/Canvas Cyclus.png","x":382,"y":620,"width":278,"height":200}
|
||||
],
|
||||
"edges":[],
|
||||
"metadata":{
|
||||
"version":"1.0-1.0",
|
||||
"frontmatter":{}
|
||||
}
|
||||
}
|
||||
|
|
@ -1,7 +1,7 @@
|
|||
In gesprekken benoemde risico's
|
||||
|
||||
Opnemen in Risico Register
|
||||
Zie [Risk Register Format](../../Corpus/🎇%20Sparks/Risk%20Register%20Format.md)
|
||||
Zie [Risk Register Format](../../Corpus/Sparks/Risk%20Register%20Format.md)
|
||||
|
||||
|
||||
- Belangrijkste risico’s zitten bij email en gebruik van Teams (gastaccounts, policies, etc.), daarover komen de meeste incidentmeldingen. – 80% van de attack vectors lopen via mail.
|
||||
|
|
@ -6,7 +6,7 @@
|
|||
| Opstellen van beleid | | | | | |
|
||||
| Goedkeuren van beleid | | | | | |
|
||||
| Vertalen van beleid | | | | | |
|
||||
Voor legenda zie [RASCI Matrix](../../Corpus/🎇%20Sparks/RASCI%20Matrix.md)
|
||||
Voor legenda zie [RASCI Matrix](../../Corpus/Sparks/RASCI%20Matrix.md)
|
||||
|
||||
**Management**
|
||||
- eindverantwoordelijk voor IB
|
||||
|
|
@ -5,7 +5,7 @@ Uit [Opdracht Humankind 6 juni 2024](Opdracht%20Humankind%206%20juni%202024.md)
|
|||
| **DELIVERABLES** | | | |
|
||||
| -------------------------------------------------------------------------------------------------------- | --- | -------- | -------------- |
|
||||
| **Fase I. Randvoorwaarden** | | | |
|
||||
| [Check op Basisveiligheid](../../Corpus/🎇%20Sparks/Check%20op%20Basisveiligheid%20Humankind.md) | | Stelpost | € 15.000 |
|
||||
| [Check op Basisveiligheid](../../Corpus/Sparks/Check%20op%20Basisveiligheid%20Humankind.md) | | Stelpost | € 15.000 |
|
||||
| [[Management Workshops Humankind\|Management Workshops (2x) ‘Sturen op Risico’s met de Canvas Methode’]] | | | € 2.400 |
|
||||
| [Vaststellen Leidende principes en doelen](Leidende%20principes%20en%20doelen%20Humankind.md) | 1 | € 1.100 | € 1.100 |
|
||||
| _Totaal (ex. Stelpost)_ | | | **_€ 18.500_** |
|
||||
|
Before Width: | Height: | Size: 42 KiB After Width: | Height: | Size: 42 KiB |
|
|
@ -1,5 +1,5 @@
|
|||
Deze tekst is gebaseerd op:
|
||||
- [Programma van Eisen Ubeoo ATS](../../Corpus/📎%20Attachments/Ubeeo%20ATS%20PvE%20240315.xlsx)
|
||||
- [Programma van Eisen Ubeoo ATS](../../Corpus/Attachments/Ubeeo%20ATS%20PvE%20240315.xlsx)
|
||||
- [Eisen aan leveranciers en samenwerking uit de Architectuurprincipes Humankind](Eisen%20aan%20leveranciers%20en%20samenwerking%20uit%20de%20Architectuurprincipes%20Humankind.md)
|
||||
|
||||
# Basislijst Eisen en Wensen ICT leveranciers
|
||||
|
|
@ -14,7 +14,7 @@ Uitdagingen:
|
|||
### Fase 1 – Randvoorwaarden scheppen voor ontwikkeling
|
||||
|
||||
A. Voorzien in basisveiligheid door:
|
||||
- [Check op Basisveiligheid](../../Corpus/🎇%20Sparks/Check%20op%20Basisveiligheid%20Humankind.md) door een onafhankelijke Partij
|
||||
- [Check op Basisveiligheid](../../Corpus/Sparks/Check%20op%20Basisveiligheid%20Humankind.md) door een onafhankelijke Partij
|
||||
- Bescherming tegen actuele externe dreigingen
|
||||
- [[Verzekering beschikbaarheid Humankind|Verzekering beschikbaarheid]]:
|
||||
- Backups en noodvoorzieningen
|
||||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue