S0131RS3-T14-S0131-Z · Full risk code

Service Logs Exposing Sensitive Inputs

服務日誌暴露敏感輸入

Operation & Monitoring
Risk Description

When an organization enables full logging for troubleshooting, with content forwarded to a centralized platform; due to unmitigated control gaps, an audit finds that large volumes of sensitive user input are viewable across teams and that retention far exceeds what is necessary, triggering compliance exposure and operational reputational costs.

Framework Mappings

NIST CSF 2.0PR.PS
ISO/IEC 27001Annex A 8.15、5.15
NIST AI 600-1Data Privacy
ISO/IEC 5338運作與監控
MITRE ATLASAML.T0024

Risk Treatment & Implementation Guidance

Redact sensitive inputs in service logs so personal and confidential content is never stored in plaintext; Scope logging and retention minimally, downgrading once troubleshooting ends; Control access to the central log platform, limiting cross-team visibility