Threat DS.T.HPDFDAuDS-V.6

URI: DS.T.HPDFDAuDS-V.6

Package: DataLifecycle

< prev | next >

Description: Encrypted data Data stored on Host cannot be updated by Process with unencrypted input from FlowsFrom: process Process manages an encrypted stored copy of data Data on Host, so if the flows of updates from FlowsFrom is not encrypted, then Process cannot update this copy of Data without a key, so this copy will become out of date.

Threat Type: Secondary Threat

Matching Pattern:

DS.T.HPDFDAuDS-V.6
MP-HPDFDAuDS-V

Finds a Host running a Process that CRUD updates locally stored Data not encrypted with keys from a vault by saving an incoming Data Flow, plus optionally the host and process managers.

CSG-DataAccessKey

Process Process has a key for encrypting or decrypting data Data.

CSG-DataFlowEncryptionToProcess

The data Data sent by FlowsFrom to Process is encrypted end-to-end (i.e. not relying on transport level encryption).