Missing access restrictions in flows

Overview

As a best practice, flows should be restricted to specific users. Omitting restrictions gives all users the possibility to invoke a flow, which is typically undesirable.

Business Impact

Increased risk of data breaches, financial loss, and reputational harm. Eroding customer trust and confidence.

Resources

Very Frequent

Incidence

How common is this issue?
50%30%
arrow down19%
lower

Exposure

How long do organizations remain exposed before fixing the problem?
9 months4 months
arrow down58%
shorter
BenchmarkWith Clayton

Frameworks

TrustediconSecureiconOrganizational SecurityiconAuthorizationiconA04:2021 – Insecure Designicon