Threat P.T.PcPr-uDS-V.6

URI: P.T.PcPr-uDS-V.6

Package: DataLifecycle

< prev | next >

Description: Process Client cannot access updates of Data from Service due to inconsistent encryption: processes Client and Service both access a copy of Data stored in encrypted form, so they need a secure way to also share the cryptographic keys used.

Threat Type: Primary Threat

Matching Pattern:

P.T.PcPr-uDS-V.6
MP-PcPr-uDS-V

Finds two distinct processes accessing the same stored copy of data not encrypted with keys from a vault, one of which receives the data (processes it as an input) but does not depend on it.

        (empty)

        (empty)

CSG-SharedKeyManagement

Processes Client and Service have secure access to a shared key used to encrypt and decrypt data Data for transfer via file or network.