← Controls / SI

SI-11 Error Handling

System and Information Integrity

Moderate High

Description

a. Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and b. Reveal error messages only to [Assignment: organization-defined personnel or roles].

Supplemental Guidance

Organizations consider the structure and content of error messages. The extent to which systems can handle error conditions is guided and informed by organizational policy and operational requirements. Exploitable information includes stack traces and implementation details; erroneous logon attempts with passwords mistakenly entered as the username; mission or business information that can be derived from, if not stated explicitly by, the information recorded; and personally identifiable information, such as account numbers, social security numbers, and credit card numbers. Error messages may also provide a covert channel for transmitting information.

Patterns that use this control (4)

Grouped by the emphasis each pattern gives it.

Compliance Mappings

ANSSI

Hygiene.29SecNumCloud.15.3

FINMA Circular 2023/1

IV.A(41)IV.C(66)

OSFI B-13

B-13.3.2

EU GDPR

Art.32(1)(b)

EU DORA

Art.9(4)(e)

RBI CSF

Annex1.6

FISC Security Guidelines

FISC.T8

HKMA TM-E-1

TME1.10.1

EU CRA

CRA.I.2l

SAMA CSF

3.2

NCA ECC

2-14

CBB TM

TM-7

CBUAE

CR-6

CBE CSF

CTO-4

SA JS2

JS2-SA

BoG CISD

CISD-IXCISD-SDLC

BCBS 239

Principle 3Principle 7Principle 9

FFIEC IS

II.C.17

EBA ICT Guidelines

3.5(c)

BOT Cyber Resilience

Ch2.5

CMMC 2.0

SI

PRA SS1/23

P3.2

FCA SYSC 13

SYSC 13.7.1

HITRUST CSF v11

10.b

OWASP MASVS v2.1

MASVS-PLATFORM-3MASVS-STORAGE-2

ISO 17799 (legacy)

12.2.112.2.212.2.312.2.4

COBIT 4.1 (legacy)

AC5