From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Unlock the full course today
Join today to access over 24,700 courses taught by industry experts.
Authorization
From the course: ISC2 Certified Secure Software Lifecycle Professional (CSSLP) (2023) Cert Prep
Authorization
- [Instructor] Strong authentication controls can go a long way toward keeping the wrong people from gaining access to sensitive data within your apps, but how can you distinguish between who should have access to certain data and who shouldn't? This is where authorization controls come into the equation. Authorization controls focus on granting users the appropriate level of access to specific resources within your app. If your users can really prove they are who they say they are, then proper authorization controls will enable those users to do what they came to do after they log in. Broken authorization controls can prevent users from being able to use the app which represents an availability risk. The bigger risk though is when someone bypasses broken authorization controls and gains access to something they shouldn't be able to access. This represents a risk to both the confidentiality and the integrity of the data. You're likely to hear the term access controls used when…
Download courses and learn on the go
Watch courses on your mobile device without an internet connection. Download courses using your iOS or Android LinkedIn Learning app.
Contents
-
-
(Locked)
Secure architecture and design patterns3m 43s
-
(Locked)
Identifying and prioritizing controls6m 15s
-
(Locked)
Traditional application architectures7m 23s
-
(Locked)
Pervasive and ubiquitous computing6m 43s
-
(Locked)
Rich internet and mobile applications7m 9s
-
(Locked)
Cloud architectures7m 8s
-
(Locked)
Embedded system considerations8m 45s
-
(Locked)
Architectural risk assessments6m 59s
-
(Locked)
Component-based systems5m 2s
-
(Locked)
Security enhancing tools4m 8s
-
(Locked)
Cognitive computing4m 37s
-
(Locked)
Control systems8m 34s
-
(Locked)
-
-
(Locked)
Components of a secure environment8m 25s
-
(Locked)
Designing network and server controls4m 22s
-
(Locked)
Designing data controls6m 25s
-
(Locked)
Secure design principles and patterns5m 6s
-
(Locked)
Secure interface design6m 49s
-
(Locked)
Security architecture and design review3m 6s
-
(Locked)
Secure operational architecture3m 37s
-
(Locked)