Skip to main content

V4.2 — Operation Level Access Control

Operation Level Access Control: 2 L3 requirement(s). V4.2.1: Verify that sensitive data and APIs are protected against Insecure Direct Object Reference (IDOR) attacks targeting crea... V4.2.2: Verify that the application or framework enforces a strong anti-CSRF mechanism to protect authenticated functionality, a...

PropertyValue
SectionV4.2
Ownerplatform

Mapped Controls

ControlTitle
SID-ACCESS-01Multi-Tenant Isolation

Source: OWASP Application Security Verification Standard 4.0.3