id: "SI-11" title: "Error Handling" family: "SI" family_name: "System and Information Integrity" sort_id: "si-11" priority: "P1" implementation_level: "system"
Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited; and
Reveal error messages only to {{ insert: param, si-11_odp }}.
Guidance
Organizations consider the structure and content of error messages. The extent to which systems can handle error conditions is guided and informed by organizational policy and operational requirements. Exploitable information includes stack traces and implementation details; erroneous logon attempts with passwords mistakenly entered as the username; mission or business information that can be derived from, if not stated explicitly by, the information recorded; and personally identifiable information, such as account numbers, social security numbers, and credit card numbers. Error messages may also provide a covert channel for transmitting information.
Assessment Objective: error messages that provide the information necessary for corrective actions are generated without revealing information that could be exploited;
Assessment Objective: error messages are revealed only to {{ insert: param, si-11_odp }}.
System and information integrity policy
system and information integrity procedures
procedures addressing system error handling
system design documentation
system configuration settings and associated documentation
documentation providing the structure and content of error messages
system audit records
system security plan
other relevant documents or records
Organizational personnel responsible for information input validation
organizational personnel with information security responsibilities
system/network administrators
system developer
Organizational processes for error handling
automated mechanisms supporting and/or implementing error handling
automated mechanisms supporting and/or implementing the management of error messages