E. of Repudiation
We don’t log personal data access because we do not process any customer data, only employee data.
Threat |
|
Your employees’ data may contain PII that is even more sensitive than the data you are storing about your customers. Employees also have citizen rights just like third parties and, as such, their data should be afforded the same protection as customers’ data with the same level of sensitivity. |
|
CAPEC |
CAPEC-150 - Collect Data from Common Resource Locations CAPEC-155 - Screen Temporary Files for Sensitive Information |
ASVS |
1.8.1 - Ensure all your data is given a classification. 1.8.2 - Ensure you have requirements for each classification of your data for each category of the CIA triad (confidentiality, integrity, and availability... |