risk
Unauthorized disclosure / breach of sensitive information
Unauthorized disclosure of information to parties not entitled to receive it, whether by insecure controls (insecurity), spillage, or authorized users induced to expose data — resulting in identity theft, economic loss, and loss of trust.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- privacy
- domain
- Data Protection & Privacy
- Incident Management & Response
- taxonomy
- iso-27005-threat
- nist-800-30-threat-event
- nist-privacy-risk
- inherent_rating
- high
Details
- risk_id
- data-breach-unauthorized-disclosure
- category
- privacy
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- iso-27005-threat
- nist-800-30-threat-event
- nist-privacy-risk
Source
No record-specific source URL is provided.
Connections
- UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Destroying data past its retention shrinks the volume of data exposable in any breach.
- UC-DATA-14 — Maintain and provide an accounting of disclosures mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- A complete, accurate disclosure register enables detection of disclosures to unentitled parties.
- UC-DATA-12 — De-identify, mask, or pseudonymize personal data mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Masked/pseudonymized data lowers the impact of any disclosure by limiting identifiability of exposed data.
- UC-DATA-11 — Control data flows, leakage, and cross-border transfers mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Enforcing approved information-flow authorizations and DLP directly prevents data leaking to parties not entitled to it.
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Validating which data/records were exposed scopes the disclosure so response, remediation, and notification can be targeted.
- UC-DATA-16 — Bind third parties handling personal data to privacy commitments mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Binding third parties to permitted-use, safeguard, and breach-notification commitments with periodic assessment directly reduces unauthorized disclosure via vendors.
- UC-DATA-04 — Restrict processing of special categories of personal data mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Heightened safeguards on special-category data reduce the likelihood and impact of exposing the most sensitive records.
- UC-DATA-15 — Record and notify unauthorized disclosures of personal data mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Logging and analyzing unauthorized disclosures is the corrective response that limits their harm and recurrence.
- UC-DATA-13 — Safeguard personal information with reasonable security mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Implementing reasonable admin/technical/physical safeguards sized to data volume/sensitivity directly reduces unauthorized disclosure/breach.
- UC-IR-06 — Respond to, contain, and eradicate declared incidents mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Containing the incident stops ongoing unauthorized exfiltration and eradication closes the weakness enabling disclosure (RS.MI mitigation).
- UC-IR-11 — Respond to information spillage with defined procedures mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Isolating and eradicating spilled sensitive/regulated information from systems and backups directly reduces the extent of unauthorized disclosure (spillage named in the risk).
- UC-DATA-10 — Protect physical media containing sensitive data mitigates Unauthorized disclosure / breach of sensitive information
- strength
- related
- rationale
- Securing and sanitizing physical media reduces unauthorized disclosure of data carried on that media.