risk
User error and mishandling of sensitive information
Authorized users make mistakes — incorrect data entry, misconfiguration, improper procedures, incorrect privilege settings, or spilling/mishandling sensitive information — causing harm to information assets without malicious intent.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- operational
- domain
- Awareness & Training
- Data Protection & Privacy
- Logging, Monitoring & Detection
- taxonomy
- iso-27005-threat
- nist-800-30-threat-event
- nist-800-30-threat-source
- iso-27005-vulnerability
- inherent_rating
- high
Details
- risk_id
- aware-user-error-mishandling
- category
- operational
- likelihood
- high
- impact
- medium
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-threat
- nist-800-30-threat-event
- nist-800-30-threat-source
- iso-27005-vulnerability
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- Incident identification and capacity/performance monitoring surface error- and misconfiguration-driven incidents, enabling correction that limits impact.
- UC-TRAIN-01 — Deliver security awareness training to all personnel mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- General awareness cuts inadvertent sensitive-info mishandling, but the operative defense against the named operational errors (misconfiguration, privilege settings) is role-based training; general training only contributes.
- UC-TRAIN-02 — Train personnel with specialized security roles and duties mitigates User error and mishandling of sensitive information
- strength
- primary
- rationale
- Role-based training for administrators directly reduces the misconfiguration and incorrect-privilege-setting errors the risk names.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- DLP on exfiltration channels catches inadvertent user spillage of sensitive information.
- UC-LOG-07 — Monitor user sessions and personnel activity mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- Monitoring personnel technology usage against acceptable-use expectations surfaces non-malicious mishandling of sensitive information.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates User error and mishandling of sensitive information
- strength
- related
- rationale
- Monitoring explicitly flags anomalous behavior indicative of errors, enabling detection and correction before harm spreads.