Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Can access control cover all matters? #32

Open
Kr0nox opened this issue Jan 29, 2024 · 0 comments
Open

Can access control cover all matters? #32

Kr0nox opened this issue Jan 29, 2024 · 0 comments
Labels
accepted Uncertainty was manually verified and entered into the archive

Comments

@Kr0nox
Copy link
Collaborator

Kr0nox commented Jan 29, 2024

Can access control cover all matters?

Description

The uncertainty related to the comprehensiveness of access control measures, questioning whether the defined rules and policies can effectively cover all possible scenarios and security concerns within a software system.

Literature Reference

Classifications

Category Option
Location Behavior
Architectural Element Type Interface
Type Recognized Ignorance
Manageability Partially Reducible
Resolution Time Runtime
Reducible by ADD No
Impact on Confidentiality Indirect
Severity of the Impact Low

Keywords

Access Control, Human Error

Example

Despite robust access control policies, an unforeseen scenario involving a new user role and resource combination revealed gaps in coverage, prompting a reassessment of access control strategies.

Related Uncertainties

Parent:

#65

Related Uncertainties:

#34, #60, #37
@Kr0nox Kr0nox added the proposal A proposed uncertainty that was not yet verified and added to the archive label Jan 29, 2024
@sebinside sebinside added accepted Uncertainty was manually verified and entered into the archive and removed proposal A proposed uncertainty that was not yet verified and added to the archive labels Feb 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
accepted Uncertainty was manually verified and entered into the archive
Projects
None yet
Development

No branches or pull requests

2 participants