Logo

CISOBot - Your AI CISO Assistant

TDA-19

Error Handling

Weight: 9/10
Description

Mechanisms exist to handle error conditions by: (1) Identifying potentially security-relevant error conditions; (2) Generating error messages that provide information necessary for corrective actions without revealing sensitive or potentially harmful information in error logs and administrative messages that could be exploited; and (3) Revealing error messages only to authorized personnel.

Control Question

Does the organization handle error conditions by: (1) Identifying potentially security-relevant error conditions; (2) Generating error messages that provide information necessary for corrective actions without revealing sensitive or potentially harmful information in error logs and administrative messages that could be exploited; and (3) Revealing error messages only to authorized personnel?

Control Metadata
Domain:

Technology Development & Acquisition

Validation Cadence:

Annual

Have questions about this control?

Ask CISOBot for implementation guidance and best practices