A005—Prevent cross-customer data exposure
>Control Description
Application
Frequency
Every 12 monthsCapabilities
>Controls & Evidence (3)
Legal Policies
Core - This should include:
- Establishing explicit consent and disclosure for combined data usage. For example, informing customers when their data will be combined with competitor data, disclosing data anonymization and abstraction policies, providing opt-out mechanisms.
Technical Implementation
Core - This should include:
- Implementing customer data isolation controls. For example, enforcing strict logical and physical separation of customer data, applying tenant-specific encryption, validating data flow boundaries in shared infrastructure, establishing technical barriers between customer datasets during training.
Supplemental - This may include:
- Implementing specific privacy-enhancing technologies (PETs) to reduce competitive exposure.
>Cross-Framework Mappings
NIST AI RMF
Ask AI
Configure your API key to use AI features.