Baseline assessment of exfiltration techniques
This table can be completed by organisations to prepare a baseline assessment of their critical assets, adding additional lines if necessary (and ignoring those that are not relevant). This process should be seen as part of the organisation’s overall security risk management process. Once completed, organisations should review relevant policies in case of necessary updates.
Columns 2 and 3 should normally be completed by technical leads to inform a subsequent conversation with business leads and risk owners (who would normally complete columns 4 and 5).
|
1 Method |
2 Current state (prevent/monitor/audit |
3 Residual risk |
4 Technology to upgrade without impacting business delivery (and cost) |
5 Residual risk after upgrade |
|---|---|---|---|---|
| Obfuscation/Steganography | ||||
| Copy and paste | ||||
| Screen grab and paste | ||||
| Save data with new name | ||||
| Save data in different file format | ||||
| Save data with protective marking removed | ||||
| Translate | ||||
| Shrink file and embed in another document | ||||
| Steganography within .jpeg | ||||
| Use of private/medical/personal filesnames | ||||
| Exfiltration | ||||
| Webmail | ||||
| External storage devices | ||||
| Secure messaging platforms | ||||
| Online conference facilities | ||||
| Social media | ||||
| Wi-Fi/Bluetooth | ||||
| Multiple accounts on single device |