rspec/rules/S6302/ask-yourself.adoc

9 lines
304 B
Plaintext

== Ask Yourself Whether
Identities obtaining all the permissions:
* only require a subset of these permissions to perform the intended function.
* have monitored activity showing that only a subset of these permissions is actually used.
There is a risk if you answered yes to any of those questions.