SENSITIVE INFORMATION: PROTECT DATA THAT COULD CAUSE HARM IF EXPOSED
Not all information carries the same level of risk. Sensitive information is information that could create significant financial, identity, privacy or security harm if it reached an unauthorized person.
THE CORE PRINCIPLE
PROTECT INFORMATION ACCORDING TO THE HARM THAT COULD RESULT FROM ITS EXPOSURE.
01 · IDENTIFY HIGH-IMPACT INFORMATION
Examples can include passwords, PINs, one-time authentication codes, recovery information, recovery phrases, financial information and sensitive identification documents.
02 · KEEP AUTHENTICATION SECRETS SECRET
A password or one-time code is not ordinary personal information. It can function as an access key. Unexpected requests for these details should be treated with extreme caution.
03 · VERIFY BEFORE SENDING DOCUMENTS
Before sending an identity document, financial document or other sensitive record, confirm the recipient, purpose and legitimate submission channel.
04 · LIMIT COPIES AND EXPOSURE
Avoid unnecessary copies of sensitive documents and information. Where practical, remove sensitive details that are not required for the purpose.
05 · CONSIDER WHERE INFORMATION IS STORED
Sensitive information can remain in email, messaging applications, cloud storage, photographs, downloads or shared devices. Know where important information exists and who can access it.
06 · RESPOND QUICKLY TO SUSPECTED EXPOSURE
If a sensitive credential or document may have been exposed, identify what was disclosed and take the appropriate protective action. For credentials, this may include changing the credential or terminating sessions; for financial information, contacting the relevant provider through a trusted channel.
EXAMPLE
Someone sends you a message requesting a photograph of your identification document and a one-time code “for verification.” The two requests should not be treated as ordinary identity checks. Stop and verify the organization and the purpose through an independent official channel.
WHAT TO DO
- Identify your highest-impact information.
- Never casually share authentication secrets.
- Verify recipients before sending sensitive documents.
- Limit unnecessary copies and exposure.
- Act promptly if sensitive information may have been exposed.
WHY THIS MATTERS
A single exposed secret can sometimes provide access to many other systems. Sensitive information deserves protection based on its potential consequences.
