Threat DS.A.PHHDS.3

URI: DS.A.PHHDS.3

Package: DataLifecycle

< prev | next >

Description: Stored copy of Data on AHost lost due to theft or destruction of Host in Space : an attacker with access to Space can physically steal or destroy device Host, removing it from the system, rendering data stored on AHost unavailable. The threat to data is distinct from the threat to the host, as Host could be replaced if the loss is detected, but that would not restore the lost copy of Data.

Threat Type: Primary Threat

Matching Pattern:

DS.A.PHHDS.3
MP-PHHDS

Finds a Physical Host located in a Space, plus data stored on the host or on a virtual host running there, plus optionally a user of the physical host.

        (empty)

        (empty)

CSG-EmbeddedHostSecurity

Host Host is locked or built into the physical environment Space such that neither it nor any of its internal storage media can be removed or altered without destroying them.

CSG-IgnorePhysicalThreatsFromWorld

Indicates that threats from as well as to the space Space can be ignored, i.e. that the risk model intentionally does not consider physical attacks from Space. This is only permitted if Space is the inferred global public space (the World) used when no locations are asserted in the model. This control strategy is a way to specify that physical security is out of scope for devices with no explicitly specified location(s), i.e. that they are considered physically secure.

CSG-PersonalDeviceProtection

Device Host is a personal device dedicated to one user, who will protect it from some types of attacks involving physical access. This particular strategy relates to threats that are blocked, affording slightly less than perfect protection because the user may be overcome by force or become temporarily less than vigilant.

CSG-PersonalDeviceSecurity

Device Host is a personal device dedicated to one user, who has been trained in basic security and will protect it from some types of attacks involving physical access. Similar to personal device protection, but more effective due to the user being able to maintain vigilance and avoid physically uncontrollable situations.