CS-W17 — Account & toegang · ISO 27001Account & access · ISO 27001
Versie:Version: 1.0-27001Proceseigenaar:Process owner: [CS Manager] — KlantGerelateerd:Related:CS-W18Klik op een stap voor details + beveiligingsmappingClick a step for details + security mapping
Doel: wachtwoord reset, gegevens wijzigen en nieuwsbrief afmelden veilig afhandelen. | Identiteit altijd verifiëren vóór een wijziging.
Goal: securely handle password reset, data changes and newsletter unsubscribe. | Always verify identity before a change.
🔒 ISO 27001-scan · dataveiligheidISO 27001 scan · data security
Toegangsbeheer-proces — kern van ISO 27001. Elke stap raakt persoonsgegevens en/of inloggegevens. De swimlane toont al de dataflow (wie raakt wat aan, in welk systeem) en de beveiligingsrisico's (identiteit eerst, nooit wachtwoord mailen). Van de 7 stappen is de beveiligingsmaatregel bij 4 al aanwezig, bij 3 uit systeem/beleid te halen (verificatienorm, toegangsrechten agent, logging-standaard). Belangrijk: de swimlane is bewijs op operationeel niveau — het ISMS-fundament (risicobeoordeling + Verklaring van Toepasselijkheid) zit erbuiten.
Access management process — core of ISO 27001. Every step touches personal data and/or credentials. The swimlane already shows the data flow (who touches what, in which system) and the security risks (identity first, never email a password). Of the 7 steps, the security control is already present for 4 and light to gather for 3 (verification norm, agent access rights, logging standard). Note: the swimlane is evidence at operational level — the ISMS core (risk assessment + Statement of Applicability) sits outside it.
4Maatregel aanwezigControl in place
3Uit systeem/beleidFrom system/policy
ISMSSoA + risico op procesniveauSoA + risk at process level
Document-IDCS-W17
VersieVersion1.0-27001
ProceseigenaarProcess ownerTeamlead / Supervisor
SoA-referentie (A.5–A.8)SoA reference (A.5–A.8)KoppelenTo link
RisicobeoordelingRisk assessmentVast te leggenTo be set