9. Collect only what you need (and delete what you don’t)
Many companies have had to answer embarrassing questions after successful attacks revealed that they retained customer credit card numbers years after the associated transactions were complete. Evaluate the inherent risk - not just the potential value - in the data you collect.
|
|