Skip to main content

V4.3 — Other Access Control Considerations

Other Access Control Considerations: 3 L3 requirement(s). V4.3.1: Verify administrative interfaces use appropriate multi-factor authentication to prevent unauthorized use. V4.3.2: Verify that directory browsing is disabled unless deliberately desired. Additionally, applications should not allow disc... V4.3.3: Verify the application has additional authorization (such as step up or adaptive authentication) for lower value systems...

PropertyValue
SectionV4.3
Ownerplatform

Mapped Controls

ControlTitle
SID-HARD-03Network Segmentation (Separate Server Ports)
SID-ACCESS-01Multi-Tenant Isolation

Source: OWASP Application Security Verification Standard 4.0.3