Skip to content

Sensitive Data Exposure categories - update business impact, steps #558

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

wesinator
Copy link

This PR updates the Sensitive Data Exposure Categories templates:

  • I wanted to update the Business Impact section to highlight these vulnerabilities could enable exploitation leading to loss of product or service availability, which would lead to direct financial loss impact.
    Reputational risk, which is the curent focus of these business impact descriptions, is secondary and less important to potential impacts to service availability.
  • Updated the steps list so it doesn't show two step 1's next to each other. I see these templates typically list the observed/actual in its own step one, this makes less sense if there is only one StR step.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant