SA-15 (9) - Use of Live Data
Control requirements
- SA-15 (9) - 0
- The organization approves, documents, and controls the use of live data in development and test environments for the information system, system component, or information system service.
Additional IBM Cloud for Financial Services specifications
- Customer data must not be placed into non-production environments. Customer data must not be consumed or utilized for the purposes of testing services.
Implementation guidance
See the resources that follow to learn more about how to implement this control.
NIST supplemental guidance
The use of live data in preproduction environments can result in significant risk to organizations. Organizations can minimize such risk by using test or dummy data during the development and testing of information systems, information system components, and information system services.