Skip to content

Data Exfiltration

What is Data Exfiltration?

The unauthorised transfer of data from within an organisation to an external destination. Data exfiltration can occur through various channels including email, USB drives, cloud uploads, and covert network channels.

Information Security

Each of these is named in at least one of the same controls as data exfiltration. The number is how many controls name both.

What the standards actually require on data exfiltration

Requirements naming data exfiltration across 6 standards, quoted from the control text.

PTES1 control

The tester must demonstrate impact in business terms by safely simulating data exfiltration of test or low sensitivity records, never extracting genuinely sensitive customer data unless explicitly authorised.

PTES-POST-3 · Data Exfiltration and Impact Demonstration

Enable Microsoft Defender for Storage, SQL, and Databases to detect anomalous access patterns and data exfiltration attempts.

DP-2 · Monitor anomalies and threats targeting sensitive data

Use of removable media is restricted, encrypted, and logged with DLP controls to prevent unauthorized data exfiltration.

IS-IV.D.3 · Removable Media Controls
FISMA1 control

44 USC 3556 - Federal Information Security Incident Center (FedCIRC, now CISA US-CERT). The CISA Director operates the federal information security incident center providing: (a) timely warnings on emerging threats;

FISMA-3556-FederalCIRC-3557-NSS · Federal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557)

HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.

HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs

UR E26 Goal 3 (Detect) requires monitoring + detection capabilities to identify cyber incidents. Logging: all CBS log security-relevant events (authentication + authorization + configuration change + privileged action + network connection + failure);

IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting · IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM

Questions people ask about data exfiltration

What is Data Exfiltration?
The unauthorised transfer of data from within an organisation to an external destination. Data exfiltration can occur through various channels including email, USB drives, cloud uploads, and covert network channels.
Why is Data Exfiltration important for compliance?
Data Exfiltration is a key concept in Information Security. Understanding data exfiltration helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Data Exfiltration?
Data Exfiltration appears in the requirement text of PTES, Azure Security Benchmark, FFIEC IT Examination Handbook, FISMA, HKMA Cyber Resilience Assessment Framework (C-RAF). Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Data Exfiltration?
Explore our compliance framework pages to see how data exfiltration applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Data Exfiltration applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.