G. of Repudiation
We log personal data access, but there is no ongoing monitoring or alerting.
Threat |
|
One of your staff has been reading or exporting data about other employees. You have just discovered this, but it has been going on for 6 months. |
|
CAPEC |
N/A |
ASVS |
1.7.2 - Ensure logs are sent securely to a remote server or to a Security Information and Event Management (SIEM) system. |
CWE |
CWE-215 - Insertion of Sensitive Information into Debugging Code |
Mitigations |
|
|