Least privileges
When developing web applications, ensure that you only provide the applications on the information system with the most minimal set of privileges necessary for the application to operate.
Each application that is developed for your environment has permissions that are very specific to the information system they are installed on. If a vulnerability exists within the information system and that vulnerability can be exercised by an attacker, then the attacker would be controlling an exploited system with the permissions of the web application. If the application was running with administrative permissions, then the attacker would be running with those permissions. Therefore, it is imperative that you ensure that your web applications ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access