Indicator

Risk description

Possible solutions

References

External services used for various areas, i.e. packing of products, security, etc.,

Infiltration of staff that could pose a security risk.

Incomplete control over the flow of goods

security requirements e.g. identity checks on employees, restricted access controls are written into contractual agreements;

monitoring compliance with these requirements;

use of different badges for external staff;

restricted or controlled access to computer systems;

supervise external services where appropriate;

establish security arrangements and or auditing procedures to ensure the integrity of the goods;

In case of temporary work (i.e. maintenance work) a list of authorised workers of the outsourced company.

SAQ 6.12

ISO 28001:2007, section A.3