logo

Database

Summary

The system must restrict access to system objects that have sensitive content. It should only allow access to authorized users.

Description

Applications usually handle personal and confidential information, such as personal identifications, social security numbers, credentials and health histories. This data should be protected as a fundamental right, and therefore be stored and transmitted using secure mechanisms that prevent access to it by unauthorized actors. Furthermore, the access control model and role assignment policy must be implemented taking these restrictions into consideration.

References

Weaknesses

Supported In

This requirement is verified in following services

Essential Plan

Yes

Advanced Plan

Yes