CS-W17 — Account & toegang · ISO 27001Account & access · ISO 27001

Versie:Version: 1.0-27001 Proceseigenaar:Process owner: [CS Manager] — Klant Gerelateerd:Related: CS-W18 Klik op een stap voor details + beveiligingsmappingClick a step for details + security mapping
Doel: wachtwoord reset, gegevens wijzigen en nieuwsbrief afmelden veilig afhandelen.  |  Identiteit altijd verifiëren vóór een wijziging.
Goal: securely handle password reset, data changes and newsletter unsubscribe.  |  Always verify identity before a change.

🔒 ISO 27001-scan · dataveiligheidISO 27001 scan · data security

Toegangsbeheer-proces — kern van ISO 27001. Elke stap raakt persoonsgegevens en/of inloggegevens. De swimlane toont al de dataflow (wie raakt wat aan, in welk systeem) en de beveiligingsrisico's (identiteit eerst, nooit wachtwoord mailen). Van de 7 stappen is de beveiligingsmaatregel bij 4 al aanwezig, bij 3 uit systeem/beleid te halen (verificatienorm, toegangsrechten agent, logging-standaard). Belangrijk: de swimlane is bewijs op operationeel niveau — het ISMS-fundament (risicobeoordeling + Verklaring van Toepasselijkheid) zit erbuiten.
Access management process — core of ISO 27001. Every step touches personal data and/or credentials. The swimlane already shows the data flow (who touches what, in which system) and the security risks (identity first, never email a password). Of the 7 steps, the security control is already present for 4 and light to gather for 3 (verification norm, agent access rights, logging standard). Note: the swimlane is evidence at operational level — the ISMS core (risk assessment + Statement of Applicability) sits outside it.
4 Maatregel aanwezigControl in place
3 Uit systeem/beleidFrom system/policy
ISMS SoA + risico op procesniveauSoA + risk at process level
Document-IDCS-W17
VersieVersion1.0-27001
ProceseigenaarProcess ownerTeamlead / Supervisor
SoA-referentie (A.5–A.8)SoA reference (A.5–A.8)KoppelenTo link
RisicobeoordelingRisk assessmentVast te leggenTo be set
Datclassificatie (stip)Data classification (dot)
OpenbaarPublic
InternInternal
PersoonsgegevensPersonal data
Bijzondere pers.geg.Special category
🔒 = maatregel-status🔒 = control status
🔒AanwezigIn place
🔒Uit systeem/beleidFrom system/policy
KlantCustomer
1
Klant: reset/wijzig/afmeldenCustomer: reset/change/unsubscribe
5
Klant bevestigt / nieuw wachtwoordCustomer confirms / new password
7
Toegang / gegevens bijgewerktAccess / data updated
AgentAgent
2
Identiteit verifiërenVerify identity
3
Actie uitvoerenPerform action
6
Ticket sluiten + notitieClose ticket + note
SysteemSystem
4
Bevestiging / reset-linkConfirmation / reset link
← Terug naar overzicht← Back to overview