rspec/rules/S6381/ask-yourself.adoc
daniel-teuchert-sonarsource 9a888ec176
APPSEC-1082 Validate S6381 ARM (#3022)
## Review

A dedicated reviewer checked the rule description successfully for:

- [ ] logical errors and incorrect information
- [ ] information gaps and missing content
- [ ] text style and tone
- [ ] PR summary and labels follow [the
guidelines](https://github.com/SonarSource/rspec/#to-modify-an-existing-rule)
2023-09-13 15:50:36 +02:00

6 lines
355 B
Plaintext

== Ask Yourself Whether
* The user, group, or service principal doesn't use the entirety of this extensive set of permissions to operate on a day-to-day basis.
* It is possible to follow the Separation of Duties principle and split permissions between multiple users, but it's not enforced.
There is a risk if you answered yes to any of these questions.