Skip to main content

Management / Logging / Threats / DEV

Inadequate Log Anonymization/Masking

CCC.Logging.TH04

Sensitive data (e.g., PII, secrets, authentication tokens) is ingested into logs without proper anonymization, masking, or redaction at source or during ingestion. This creates a significant data exposure risk, particularly for data not intended for broad log access.

Related Capabilities

IDTitleDescription
CCC.Logging.CP06Log Filtering & TransformationAbility to to filter, normalise, and transform raw log data at ingestion to optimise storage and enhance usability.
CCC.Logging.CP08Retention PoliciesAbility to define and enforce granular retention periods for different log types based on regulatory requirements and internal policies.

Related Controls

IDTitleDescription
CCC.Logging.CN04Restrict Field And Log Type AccessConfigure access to logs to follow the principle of least privilege in particular where technically possible limit the log fields users have access to to prevent accidental exposure to sensitive information such as PII.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1530Data from Local System
MITRE-ATT&CKT1537Transfer Data to Cloud Account
MITRE-ATT&CKT1565Data Manipulation (if attacker is masking their own activity)