Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

new req for OWASP embedded Top 10 Best Practice E9 #35

Open
BenGardiner opened this issue Jun 14, 2021 · 0 comments
Open

new req for OWASP embedded Top 10 Best Practice E9 #35

BenGardiner opened this issue Jun 14, 2021 · 0 comments

Comments

@BenGardiner
Copy link
Member

at the 20210614 meeting it was agreed that there is no matching TSRM requirement for OWASP embedded app sec best practice E9 and that there should be one

E9 It is critical to limit the collection, storage, and sharing of both personally identifiable information (PII) as well as sensitive personal information (SPI). Leaked information such as Social Security Numbers can lead to customers being compromised which could have legal repercussions for manufacturers. If information of this nature must be gathered, it is important to follow the concepts of Privacy-by-Design.

  • add a new requirement with E9 as the xref and review existing public references for other relevant xrefs.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant