{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Data Protection & Privacy","Network & Communications Security","Logging, Monitoring & Detection"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","description":"Adversary (outsider, insider, nation-state, or competitor) installs malware or sniffers to locate and exfiltrate sensitive/proprietary information, or steals data by external actors — including systems-security losses from hacking.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"critical","likelihood":"medium","risk_id":"data-exfiltration-espionage","taxonomies":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"id":"risk:data-exfiltration-espionage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","sourceIds":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Data exfiltration and theft of information by attackers","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:002d111d2b8052d42389da2b65af0f9098a52e1ca7432dd6ddf2ba5f3acac42c","properties":{"rationale":"Disabling unneeded I/O ports/devices blocks removable-media exfiltration, and prohibiting remote camera/mic activation prevents espionage collection.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-12-3fbb3db4.json","sourceId":"uc:UC-NET-12","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:06787cf328f510260906f3f6e8195ad05fb90c275aed6cc084f6f1603955f478","properties":{"rationale":"Reviewing provider logs and monitoring their activity detects data theft routed through third-party channels.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08ecff12261a3a3aff991e1d5c92545f9d51ff8832b3a40eee13455fa6368b8e","properties":{"rationale":"Data-leakage-prevention on systems/channels plus technical flow-control directly block exfiltration of sensitive data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1993a983f2a09427091e49375da5e2f760da75d2de3cfbb7f2308f246ceafba4","properties":{"rationale":"Protecting and retaining logs preserves the forensic evidence attackers would erase after locating and stealing data.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","sourceId":"uc:UC-LOG-03","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9dadfb07326923527488fb657fa7640ae4bb4471959de932d334a486591a2f4","properties":{"rationale":"Monitoring for unauthorized connections and anomalous behavior (SI-4) detects exfiltration such as anomalous outbound transfers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d253870d8a042796fc22983c940c69373fead8d84e7a7844fc3c88e556b1106a","properties":{"rationale":"Correlating events (e.g., beaconing plus large transfers) against threat-intel indicators detects exfiltration patterns.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8d42bf85ad8b78bd895f84c62c95e0675bfd71b283e9534f0fc444210b33e94","properties":{"rationale":"Logging access to sensitive/regulated (e.g., cardholder) data provides a targeted detection input for locating and investigating exfiltration.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dbd8cd0a2ccfdcaa276c5cdef7b7d411014f86203a8f31134852fab9d0872033","properties":{"rationale":"Session and personnel-usage monitoring detects insiders locating or moving sensitive data for theft.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-07-659fa92d.json","sourceId":"uc:UC-LOG-07","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e9a4ed6bfb57dcfb31b1962acabc55ba4c83b828e8960ce0d3dc1849db0621a7","properties":{"rationale":"Complete, accurately time-synced records enable reliable reconstruction of an exfiltration timeline during investigation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-02-0d3519a4.json","sourceId":"uc:UC-LOG-02","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ef6b2eb12e590b37a925e130949f3959cb02d9bfc83debc66312eb30fd69fc52","properties":{"rationale":"Enforcing mandatory cross-domain policy that permits only authorized data types and flow directions blocks unauthorized data egress between domains.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-14-bacae152.json","sourceId":"uc:UC-NET-14","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc85170dc1902a9c028c0d699d79713d128c8547d3992202428ba1706f80dc7a","properties":{"rationale":"Malware and network defenses directly counter the malware and sniffers adversaries install to locate and exfiltrate data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-13-aa7feb8e.json","sourceId":"uc:UC-BCDR-13","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ffd8d149aaba0da444f2773512dc412cf75c85607cb3711369ba7d2a9447c03e","properties":{"rationale":"Declaring data-breach incidents against defined thresholds and notifying regulators/individuals reduces the impact of data theft.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"}],"schemaVersion":1}
