Data Exfiltration
What is Data Exfiltration?
The unauthorised transfer of data from within an organisation to an external destination. Data exfiltration can occur through various channels including email, USB drives, cloud uploads, and covert network channels.
Terms that appear alongside data exfiltration
Each of these is named in at least one of the same controls as data exfiltration. The number is how many controls name both.
- ransomware 3 shared controls
- lateral movement 3 shared controls
- critical infrastructure 2 shared controls
- anomaly detection 2 shared controls
- chain of custody 2 shared controls
- authentication 2 shared controls
Frameworks that govern data exfiltration
What the standards actually require on data exfiltration
Requirements naming data exfiltration across 6 standards, quoted from the control text.
The tester must demonstrate impact in business terms by safely simulating data exfiltration of test or low sensitivity records, never extracting genuinely sensitive customer data unless explicitly authorised.
PTES-POST-3 · Data Exfiltration and Impact Demonstration →Enable Microsoft Defender for Storage, SQL, and Databases to detect anomalous access patterns and data exfiltration attempts.
DP-2 · Monitor anomalies and threats targeting sensitive data →Use of removable media is restricted, encrypted, and logged with DLP controls to prevent unauthorized data exfiltration.
IS-IV.D.3 · Removable Media Controls →44 USC 3556 - Federal Information Security Incident Center (FedCIRC, now CISA US-CERT). The CISA Director operates the federal information security incident center providing: (a) timely warnings on emerging threats;
FISMA-3556-FederalCIRC-3557-NSS · Federal Information Security Incident Center (44 USC 3556) + National Security Systems Exclusion (44 USC 3557) →HKMA C-RAF iCAST (Intelligence-led Cyber Attack Simulation Testing) - mandatory for HIGH inherent risk AIs + optional for medium tier + modeled on UK CBEST + ECB TIBER-EU (verified separately in this corpus) + intelligence-led red team testing methodology.
HKMA-CRAF-iCAST-RedTeam-PurpleTeam-IntelLed · HKMA C-RAF iCAST (Intelligence-Led Cyber Attack Simulation Testing) for HIGH Inherent Risk AIs →UR E26 Goal 3 (Detect) requires monitoring + detection capabilities to identify cyber incidents. Logging: all CBS log security-relevant events (authentication + authorization + configuration change + privileged action + network connection + failure);
IACS-UR-E26-Detect-Logging-Monitoring-Audit-Alerting · IACS UR E26 Detect Goal - Logging + Network Monitoring + Audit Trail + Alerting + SIEM →Questions people ask about data exfiltration
What is Data Exfiltration?
Why is Data Exfiltration important for compliance?
Which compliance frameworks address Data Exfiltration?
Where can I learn more about Data Exfiltration?
See how Data Exfiltration applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.