Residual Data in Shared Hardware Memory
共享硬體記憶體殘留
Operation & Monitoring
Risk Description
When an organization processes sensitive content in a shared computing environment without assessing memory residue risk; due to unmitigated control gaps, the possibility that subsequent users can retrieve residual data invalidates the organization's confidentiality assurances, requiring a full review of shared environment usage policy, triggering compliance exposure and operational reputational costs.
Framework Mappings
NIST CSF 2.0PR.IR
ISO/IEC 27001Annex A 8.10
MITRE ATLASAML.T0024
NIST AI 600-1Data Privacy
ISO/IEC 5338運作與監控
Risk Treatment & Implementation Guidance
Force GPU memory clearing after use in shared environments so residual data cannot be recovered by subsequent users; Prefer dedicated or physically isolated resources for highly sensitive content; Map sensitivity levels to permitted environment types in the shared-use policy