From the course: CSSLP Cert Prep: 1 Secure Software Concepts

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Accountability

Accountability

From the course: CSSLP Cert Prep: 1 Secure Software Concepts

Start my 1-month free trial

Accountability

- [Instructor] Over time, applications can generate a lot of traffic. Every log in, every form submission, and every search query represents someone doing something with the access that you've granted them. The question is though, are they using that access appropriately? Your access controls are going to be largely preventative, designed to make sure that users can only do what they're supposed to do. Users are clever though, and so are criminals. If they find a way to do something they shouldn't be doing, then you need to be able to catch them in the act. There's an old Russian proverb that speaks to this exact concern, trust, but verify. We refer to this concept as accountability. It means that you're able to determine who did what within your app, it also means that you know the exact date and time that they did it. It sounds simple right? Well let's just say it's easier said than done. When it comes to…

Contents