Data Misuse
Threats relating to the mishandling of sensitive customer data
Affected entity: MNO
Risk: Unauthorized access to user data and interception of data in transit.
Vulnerability: Weak encryption practices or sending sensitive information in clear text over insecure traffic channels like SMS and USSD (SD: communication security)
Affected entity: DFS Provider and Third-party providers
Risk: Exposure of Sensitive data
Vulnerability: Inadequate data protection controls (SD: privacy)
Risk: Exposure of customer sensitive information during transactions or through APIs (SD: privacy)
Control 5.3: DFS providers should restrict the sharing of information to be only the minimum amount required for transactions with third parties and service providers
Vulnerability: Weak encryption on the API interfaces (SD: privacy)
Last updated