S0130RS3-T14-S0130-Z · Full risk code

Residual Data in Shared Hardware Memory

共享硬體記憶體殘留

Operation & Monitoring
Risk Description

When an organization processes sensitive content in a shared computing environment without assessing memory residue risk; due to unmitigated control gaps, the possibility that subsequent users can retrieve residual data invalidates the organization's confidentiality assurances, requiring a full review of shared environment usage policy, triggering compliance exposure and operational reputational costs.

Framework Mappings

NIST CSF 2.0PR.IR
ISO/IEC 27001Annex A 8.10
MITRE ATLASAML.T0024
NIST AI 600-1Data Privacy
ISO/IEC 5338運作與監控

Risk Treatment & Implementation Guidance

Force GPU memory clearing after use in shared environments so residual data cannot be recovered by subsequent users; Prefer dedicated or physically isolated resources for highly sensitive content; Map sensitivity levels to permitted environment types in the shared-use policy