Per PTES Threat Modeling phase: model threats. Requirements include (a) identify threat agents relevant to target including external + internal + nation-state + criminal + (b) model attack scenarios + paths + (c) determine motivations + capabilities + (d) align scenarios to engagement objectives + (e) document threat model + (f) integrate with vulnerability analysis + exploitation.
What else in your programme already covers this
This control maps to 194 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process