ISC2 CISSP (Certified Information Systems Security Professional)Security Architecture and EngineeringMedium
A financial institution is developing a new mobile banking application. During the design phase, the security team identifies a significant risk related to unsecured data storage on the client device. Which specific mobile system vulnerability category does this fall under, and what is a common mitigation strategy?
- ASide-Channel Attacks; implement anti-tampering mechanisms.
- BInsecure Data Storage; encrypt sensitive data at rest on the device.
- CBroken Cryptography; use stronger encryption algorithms.
- DImproper Session Handling; implement token-based authentication.
Show answer & explanationAnswer & explanation
Correct answer: B. Insecure Data Storage; encrypt sensitive data at rest on the device.
Unsecured data storage on a mobile device is a direct concern under the 'Insecure Data Storage' vulnerability. The primary mitigation is to encrypt all sensitive data when it's stored on the device, ensuring confidentiality even if the device is lost or compromised.
Why the other options are wrong
- A. Side-Channel Attacks exploit information leakage from physical implementation, which is a different class of vulnerability.
- C. Broken Cryptography relates to weak or improperly implemented cryptographic functions, not general data storage.
- D. Improper Session Handling deals with session management vulnerabilities, not data at rest.
Insecure Data Storage (Mobile)
A mobile application vulnerability where sensitive information is stored in an unencrypted or otherwise unprotected manner on the device's file system.
- Can include databases, configuration files, logs, and user inputs.
- Mitigated by encrypting sensitive data at rest.
- Often results from developers' oversight or misunderstanding of device storage.
Memory trick: Mobile Storage is Sensitive, Encrypt It!