Vacuously: data is not stored on the client side.
\end{result}
- \item\pass{} Verify accessing sensitive data is logged, if the data is
+ \item\fail{} Verify accessing sensitive data is logged, if the data is
collected under relevant data protection directives or
where logging of accesses is required.
to mitigate memory dumping attacks.
\begin{result}
- I consider this outside of the scope of the \CMS{}'s security requirements, as it is written in, and thus relies on the (memory) security of, \PHP{}.
+ We consider this outside of the scope of the \CMS{}'s security requirements, as it is written in, and thus relies on the (memory) security of, \PHP{}.
\end{result}
\end{enumerate}