ISC2 CISSP (Certified Information Systems Security Professional)Software Development SecurityMedium
A financial institution is developing a new mobile banking application. The security architect is concerned about potential data leakage from the application's local storage if the device is compromised. Which of the following security controls would best mitigate this risk?
- AImplementing robust server-side authentication and authorization.
- BPerforming regular code reviews to identify insecure data handling.
- CEncrypting all sensitive data stored locally on the mobile device.
- DUtilizing transport layer security (TLS) for all network communication.
Show answer & explanationAnswer & explanation
Correct answer: C. Encrypting all sensitive data stored locally on the mobile device.
Encrypting sensitive data stored locally on the mobile device ensures that even if the device is compromised and data is accessed, it remains unintelligible without the decryption key, directly mitigating data leakage from local storage.
Why the other options are wrong
- A. Server-side controls protect data in transit or at rest on the server, not data locally stored on a compromised client device.
- B. Code reviews can help identify potential vulnerabilities, but encryption is the direct control that mitigates the risk of data leakage once the data is already on the device and the device is compromised.
- D. TLS protects data in transit between the device and server, but not data at rest on the device's local storage.
Data at Rest Encryption
The process of encrypting data that is stored on a persistent storage medium (e.g., hard drive, mobile device, cloud storage) to protect it from unauthorized access.
- Protects data even if storage device is stolen/compromised
- Requires effective key management
- Applies to local files, databases, backups
Memory trick: Local data's safe, if encrypted it's kept, from prying eyes, secrets well-slept.