F of Information Disclosure
Personal data is being saved on unencrypted media.
Threat |
|
You are saving personal data on a USB key or your computer without having either full disk encryption or encrypting the data directly, so if a thief were to steal your computer, they could read all of your personal or your company’s data. |
|
CAPEC |
CAPEC-507 - Physical Theft |
ASVS |
1.8.2 - Ensure the level of protection (confidentiality, integrity, and availability) matches the security and privacy classification of the data. 6.1.1 - Ensure all PII is encrypted at rest in line with the General Data Protection Regulation (GDPR) requirements. 6.1.2 - Ensure all medical data is encrypted at rest in line with the Health Insurance Portability and Accountability Act (HIPAA) requirements... |