Sensitive Private Data

V8.3.1

Verify that sensitive data is sent to the server in the HTTP message body or headers, and that query string parameters from any HTTP verb do not contain sensitive data.

Level 1 required: True

Level 2 required: True

Level 3 required: True

CWE: 319

V8.3.2

Verify that users have a method to remove or export their data on demand.

Level 1 required: True

Level 2 required: True

Level 3 required: True

CWE: 212

V8.3.3

Verify that users are provided clear language regarding collection and use of supplied personal information and that users have provided opt-in consent for the use of that data before it is used in any way.

Level 1 required: True

Level 2 required: True

Level 3 required: True

CWE: 285

V8.3.4

Verify that all sensitive data created and processed by the application has been identified, and ensure that a policy is in place on how to deal with sensitive data. (C8)

Level 1 required: True

Level 2 required: True

Level 3 required: True

CWE: 200

V8.3.5

Verify accessing sensitive data is audited (without logging the sensitive data itself), if the data is collected under relevant data protection directives or where logging of access is required.

Level 1 required: False

Level 2 required: True

Level 3 required: True

CWE: 532

V8.3.6

Verify that sensitive information contained in memory is overwritten as soon as it is no longer required to mitigate memory dumping attacks, using zeroes or random data.

Level 1 required: False

Level 2 required: True

Level 3 required: True

CWE: 226

V8.3.7

Verify that sensitive or private information that is required to be encrypted, is encrypted using approved algorithms that provide both confidentiality and integrity. (C8)

Level 1 required: False

Level 2 required: True

Level 3 required: True

CWE: 327

V8.3.8

Verify that sensitive personal information is subject to data retention classification, such that old or out of date data is deleted automatically, on a schedule, or as the situation requires.

Level 1 required: False

Level 2 required: True

Level 3 required: True

CWE: 285

Disclaimer:

Credit via OWASP ASVS. For more information visit The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v3.0 license.

Github logo View source on GitHub

Loading comments 0%

Provided by dotNET lab

This website is created, hosted and provided by dotNET lab. dotNET lab provides training and guidance on secure software development. Contact us to get in touch!

OWASP Cornucopia

OWASP Cornucopia is originally created by Colin Watson. It is open source and can be downloaded free of charge from the OWASP website. It is is free to use. It is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one. OWASP does not endorse or recommend commercial products or services. OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 3.0 license and is © 2012-2016 OWASP Foundation.