Indicator |
Risk description |
Possible solutions |
References |
External services used for various areas, i.e. packing of products, security, etc., |
Infiltration of staff that could pose a security risk. Incomplete control over the flow of goods |
security requirements e.g. identity checks on employees, restricted access controls are written into contractual agreements; monitoring compliance with these requirements; use of different badges for external staff; restricted or controlled access to computer systems; supervise external services where appropriate; establish security arrangements and or auditing procedures to ensure the integrity of the goods; In case of temporary work (i.e. maintenance work) a list of authorised workers of the outsourced company. |
SAQ 6.12 ISO 28001:2007, section A.3 |