Other Authorization Considerations
V8.4.1
Verify that multi-tenant applications use cross-tenant controls to ensure consumer operations will never affect tenants with which they do not have permissions to interact.
Required for Level 2 and 3
Related CAPEC™ Requirements
V8.4.2
Verify that access to administrative interfaces incorporates multiple layers of security, including continuous consumer identity verification, device security posture assessment, and contextual risk analysis, ensuring that network location or trusted endpoints are not the sole factors for authorization even though they may reduce the likelihood of unauthorized access.
Required for Level 3
Related CAPEC™ Requirements
CAPEC™ (3.9): 1, 114, 115, 116, 133, 151, 156, 176, 179, 180, 233, 49, 554, 69, 75
Disclaimer
Credit via OWASP ASVS.For more information visit: The OWASP ASVS Project or Github respository.. OWASP ASVS is under the Creative Commons Attribution-Share Alike v4.0 license.