Exfiltration
PCIComplianceHubLast updated
Moving data out of an entity's control without authorisation: the step in a compromise where the attacker takes what they came for. E-skimming exfiltrates card data straight from the shopper's browser; a server compromise exfiltrates it from storage or logs. Egress controls under 1.3.2, which restrict outbound traffic from the CDE to what is necessary, and change detection under 11.6.1, which watches for scripts posting to new destinations, are the controls written against it.