Access Control is necessary for security at almost every layer within a web application. This webcast will cover several of the critical access control anti-patterns commonly found during website security audits. These access control anti-patterns include hard-coded security policies, lack of horizontal access control, direct object reference issues, and "fail open" access control mechanisms, to name a few. In reviewing these and other access control anti-patterns, we will come up with a series of positive access control principles that make up a robust access-control mechanism for any web- or API-based application.
Broadcast on
in Webcasts
Access Control Design Best Practices
July 22, 2020 | 12:00 PM PT | 3:00 PM ET
Contributors
James Manico
VP of Security Architecture, WhiteHat Security
DevSecOps & Application Security
access control application security audit
Share With Your Community