PTES
Evidence, data protection and post-test cleanup – PTES

PTES PTES-4.1: Protect and, where required, avoid holding the organisation's sensitive data

The organisation and provider agree how sensitive data encountered during the test is handled: certain data (for example regulated personal or health information) should not be viewed or downloaded, and access is instead evidenced without taking the data (for example proof of access such as file permissions or record counts rather than the content), with care that identifiers are not exposed in the evidence itself. Where regulated data is involved, the systems and their locations used for any collection are agreed so that no applicable law is broken, and the acceptable-use position that lets the testers use discovered data as leverage is confirmed against the organisation's own policies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27002:2022 · 2 controls

  • 5.34 Privacy and protection of PII
  • 8.11 Data masking

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Evidence, data protection and post-test cleanup – PTES

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.