Authorization Documentation
V8.1.1
Verify that authorization documentation defines rules for restricting function-level and data-specific access based on consumer permissions and resource attributes.
Required for Level 1, 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 1, 116, 122, 126, 133, 143, 144, 149, 155, 176, 179, 180, 203, 207, 212, 240, 54, 554, 58, 75, 87
V8.1.2
Verify that authorization documentation defines rules for field-level access restrictions (both read and write) based on consumer permissions and resource attributes. Note that these rules might depend on other attribute values of the relevant data object, such as state or status.
Required for Level 2 and 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 122, 207, 212, 554, 58
V8.1.3
Verify that the application's documentation defines the environmental and contextual attributes (including but not limited to, time of day, user location, IP address, or device) that are used in the application to make security decisions, including those pertaining to authentication and authorization.
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 114, 151, 156, 176, 195, 465, 510, 543, 554, 593, 633, 98
V8.1.4
Verify that authentication and authorization documentation defines how environmental and contextual factors are used in decision-making, in addition to function-level, data-specific, and field-level authorization. This should include the attributes evaluated, thresholds for risk, and actions taken (e.g., allow, challenge, deny, step-up authentication).
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 1, 114, 116, 133, 151, 156, 176, 179, 180, 195, 207, 465, 510, 543, 554, 593, 633, 75, 98
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.