Skip to main content

Restrict system objects

Requirement#

The system must restrict access to system objects that have sensitive content. It should only allow access to authorized users.

Description#

Applications usually handle personal and confidential information, such as personal identifications, social security numbers, credentials and health histories. This data should be protected as a fundamental right, and therefore be stored and transmitted using secure mechanisms that prevent access to it by unauthorized actors. Furthermore, the access control model and role assignment policy must be implemented taking these restrictions into consideration.

References#