Controls
Bijgewerkt 2026-09-23 4 van 15 op ordeWat we op orde hebben, per onderwerp. Groen betekent dat de controls erachter voldaan zijn en onderbouwd met actueel bewijs of een geslaagde automatische controle; grijs betekent nog niet.
Beveiliging van de infrastructuur
1 van 5 op orde- Information is classified and labelled according to the classification scheme — op orde
- All information and IT assets are in an up-to-date register with an owner — nog niet op orde
- Backups are made, protected and periodically restore-tested — nog niet op orde
- Logs are monitored; deviations lead to follow-up — nog niet op orde
- Relevant events are logged and protected against manipulation — nog niet op orde
Organisatorische beveiliging
3 van 5 op orde- All employees follow awareness training periodically — op orde
- Policy and underlying documents are established and current — op orde
- Roles, tasks and responsibilities for security are assigned — op orde
- Management establishes the information security policy and promotes it — nog niet op orde
- Suppliers are assessed risk-based before and during the relationship — nog niet op orde
Beveiliging van het product
0 van 3 op orde- Access is granted on the basis of least privilege and need-to-know — nog niet op orde
- MFA is enforced for external access and management interfaces — nog niet op orde
- MFA is enforced for privileged accounts — nog niet op orde
Interne procedures
0 van 2 op orde- Incident response has roles, procedures and escalation paths — nog niet op orde
- Incidents are reported, registered and classified — nog niet op orde