Get a Pentest and security assessment of your IT network.

News

Role-based access control is fine who needs attribute-based access control?

CSO security expert: There are myths of authentication and authorization. He says attribute-based access control (ABAC) is overkill, but role-based control (RBAC) should be used. The problem is that people are being assigned roles based on manual processes and requests, not by automatic decisions driven by users attributes. Roles are like taxes, easy to dole out and rarely taken back, he says. Fetching someone’s status via a database is a rudimentary process that can factor into the security decisions that your platform makes that decision.”]

Source: https://www.csoonline.com/article/3254137/role-based-access-control-is-fine-who-needs-attribute-based-access-control.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2