Threat DF.A.HPDODF-V.6.2

URI: DF.A.HPDODF-V.6.2

Package: DataLifecycle

< prev | next >

Description: Process Process cannot decrypt output Data computed in the encrypted domain: the flow of output data Data from Process to FlowsTo should be decrypted, but process Process computed it in an encrypted domain (using a secure computation method such as homomorphic encryption) and has no means to decrypt the result before sending it.

Threat Type: Secondary Threat

Matching Pattern:

DF.A.HPDODF-V.6.2
MP-HPDODF-V

Finds a Host running a Process that creates (possibly from user input) a Data Flow not encrypted with keys from a vault, to send to a destination process, plus the associated Data and Data Output assets, and optionally the Process and Host managers.

CSG-DataFlowEncryptionFromProcess

The data Data sent by Process to FlowsTo is encrypted end-to-end (i.e. not relying on transport level encryption).