gcdevops / HRWhiteListing

MIT License
2 stars 0 forks source link

Scan for sensitive fields #222

Closed jaysonmc closed 4 years ago

jaysonmc commented 4 years ago

AC-3 (9) | Access Enforcement

Review information before it is released publically to ensure it does not contain sensitive information.


Create a script (to be run as part of the deployment process) that returns warnings (or errors) if words that would indicate protected information are found (perhaps in the models folder, or where the fields are defined).

Examples of words to scan for

Warnings: PA (non-case sensitive) - Martial, Medical, Financial, Budget, Date of Birth / DoB

Errors: PB+ (non-case sensitive) - SIN, Social Insurance, Personal, PRI

jaysonmc commented 4 years ago

Review information before it is released publically to ensure it does not contain sensitive information.