Threat D.E.D-Hu-Th.9

URI: D.E.D-Hu-Th.9

Package: Privacy

< prev | next >

Description: Data Data is not related to any human: personal data must have a 'relatesTo' link to its Human data subject. Data Data does not have such a link. If Data is personal data, then you should add the data subject to the model if they are not yet included (even if they are not users of the system) and add the relationship indicating the data relates to that subject. If in fact Data is not personal data, select the control strategy to signal to SSM that the absence of such a link is not an error.

Threat Type: Primary Threat

Matching Pattern:

D.E.D-Hu-Th.9
MP-D-Hu-Th

Finds a solo Data asset which is not spam, not created by a Sensor or stored on an IoT Thing, and does not relate to a human subject.

        (empty)

        (empty)

        (empty)

        (empty)

CSG-ImpersonalData

Signals that the data asset Data is not related to a human data subject, thus addressing modelling error threats representing the possibility that the relationship to a data subject has been overlooked.