AC-23 Data Mining Protection

Access Control

Description

Employ [Assignment: organization-defined data mining prevention and detection techniques] for [Assignment: organization-defined data storage objects] to detect and protect against unauthorized data mining.

Supplemental Guidance

Data storage objects include database records and database fields. Sensitive information can be extracted from data warehouses, databases, and data storage objects through data mining. Data mining prevention and detection techniques include limiting the types of responses provided to database queries, limiting the number or frequency of database queries to increase the work factor needed to determine the contents of databases, and notifying organizational personnel when atypical database queries or accesses occur.

Changes from Rev 4

No significant changes from Rev 4.

Compliance Mappings

COBIT 2019

DSS05

NIS2 Directive

Art. 21(2)(i)

MAS TRM

9

BSI IT-Grundschutz

ORP.4

RBI CSF

Annex1.15

CBUAE

CR-5

CBE CSF

CTO-2

SA JS2

JS2-8.2

CBN CSF

Part3.4

SEBI CSCRF

PR.DS