Unintended Disclosure of Personal Information
Threats resulting in user data being inadvertently exposed.
Affected entity: DFS Provider
Risk: The risk of exposure of personally identifiable information occurs because of the following vulnerability
Vulnerability: Inadequate oversight and controls in test environments (SD: privacy)
Affected entity: Third-Party Provider
Risk: Exposure of sensitive information occurs because of the following vulnerabilities: |
Vulnerability: Exposure of customer-sensitive information in transactions or through APIs (SD: privacy)
Vulnerability: Insufficient data protection controls (SD: privacy)
Control 17.3: Providers should ensure that customer-sensitive data is removed from environments such as trace logs (for example, cash retrieval voucher codes, bank account numbers, and credentials). Use place holders whenever possible to represent this data in log files.
