Organization needs to choose, safeguard, and handle test information thoughtfully to ensure that testing remains relevant and operational information used for testing is protected. Information used in testing should receive the same level of attention and care as operational information to prevent any information leaking outside the organization.
The data and other materials used for testing should be carefully selected and protected.
Production information that contains personal or other confidential information should not be used for testing purposes.
The use of production data for testing purposes should be avoided. If confidential information is used in testing, the following security measures should be used: