---
name: framework-financial-services-controls-si-11
title: SI-11 - Error Handling
description: Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited.
last-updated: 2025-02-26
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services-controls?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# SI-11 - Error Handling
{: #si-11}

## Control requirements
{: #control-requirements}



### SI-11 (a)


Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited.


### SI-11 (b)


Reveal error messages only to _[Assignment: organization-defined personnel or roles]_.









## Implementation guidance
{: #implementation-guidance}

See the resources that follow to learn more about how to implement this control.


- [Operational logging](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-shared-logging-operational&format=markdown)






## NIST supplemental guidance
{: #nist-supplemental-guidance}

Organizations consider the structure and content of error messages. The extent to which systems can handle error conditions is guided and informed by organizational policy and operational requirements. Exploitable information includes stack traces and implementation details; erroneous logon attempts with passwords mistakenly entered as the username; mission or business information that can be derived from, if not stated explicitly by, the information recorded; and personally identifiable information, such as account numbers, social security numbers, and credit card numbers. Error messages may also provide a covert channel for transmitting information.