Unintended Disclosure of Personal Information

Threats resulting in user data being inadvertently exposed.

Affected entity: DFS Provider

Risk: The risk of exposure of personally identifiable information occurs because of the following vulnerability

  • Vulnerability: Inadequate oversight and controls in test environments (SD: privacy)

Affected entity: Third-Party Provider

Risk: Exposure of sensitive information occurs because of the following vulnerabilities: |

  • Vulnerability: Exposure of customer-sensitive information in transactions or through APIs (SD: privacy)

  • Vulnerability: Insufficient data protection controls (SD: privacy)

  • Control 17.3: Providers should ensure that customer-sensitive data is removed from environments such as trace logs (for example, cash retrieval voucher codes, bank account numbers, and credentials). Use place holders whenever possible to represent this data in log files.

Last updated