9. of Privacy
Your product team avoids required controls for personal data as they move it outside of regulated and hardened environments.
Threat |
|
If you work with PII, health, or financial data, you will have to meet certain regulatory requirements, such as encrypting personal information at rest and in transit. Members of your product team copy the production database onto their laptops to test new features without encrypting it locally. |
|
GDPR |
N/A |
CCPA and HIIPA |
https://aspe.hhs.gov/reports/health-insurance-portability-accountability-act-1996 |
OECD |
N/A |
Mitigations |
|
|