Expert Advice Community

Guest

Template content about spam e-mail

  Quote
Guest
Guest user Created:   Sep 12, 2019 Last commented:   Sep 13, 2019

Template content about spam e-mail

Form the IT Security Policy 3.14: Should a user receive a spam e-mail, he / she must inform [job title].) This may be something to think about for (specific) phishing mails, but is certainly not suitable for spam, here 98% of all email is spam and once in a while one gets through the filters.

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 13, 2019

First it is important to note that you must consider the results of risk assessment to decide if this rule is needed or not in you policy.

Considering that, this requirement is included in the IT Security Policy exactly to treat this “once in a while” situation for spam e-mail, which can be used as a metric to evaluate the performance of your spam filter or as a trigger to an abnormal situation.

For example, in a situation where you start receiving a significant number of user reports about spam e-mail in a short period of time, this may mean that something is wrong with the filter, or that a DOS attack may be in progress.

Quote
0 0
Guest
Guest user Sep 13, 2019

Thanks, however based on experience in a corporate environment, there are better monitors for filter and DOS, and users reporting spam create unnecessary work for limited resources. Reporting spam is a DOS on the support organization. From a risk based approach, I cannot see where spam would outweigh (spear)phishing.

Quote
0 0
Expert
Rhand Leal Sep 13, 2019

If the results of your risk assessment support the decision about treating (spear)phishing instead of email spam you can edit the document accordingly. The template is fully editable and the standard does not prescribe the details about controls Implementation.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 12, 2019

Sep 13, 2019

Suggested Topics