Threat DF.A.PmDFI-kDADFI.6

URI: DF.A.PmDFI-kDADFI.6

Package: DataLifecycle

< prev | next >

Description: Encrypted data Data cannot be forwarded by Process to FlowsTo: if the flow of data Data to Process is encrypted, it cannot be forwarded to FlowsTo which expects it to be unencrypted.

Threat Type: Primary Threat

Matching Pattern:

DF.A.PmDFI-kDADFI.6
MP-PmDFI-kDADFI

Finds a Process that forwards flowing data from one or more sources but not from local storage in the direction of a data consumer, plus the associated Data and Data Access assets. The forwarding Process is matched twice, so it can be referred to by either role name.

        (empty)

        (empty)

CSG-DataAccessKey

Process Process has a key for encrypting or decrypting data Data.

CSG-DataFlowEncryption

The data Data flowing between processes FlowsFrom and FlowsTo is encrypted by the two processes (i.e. not relying on transport level encryption).