Evidence of All Privileged Users to Application In-Scope
Provide system screenshots or a system-generated list demonstrating which users and systems are able to make changes to your in-scope application. Changes to the in-scope application include the ability to:
Add, modify, or delete customer application configurations
Add, modify, or delete customer data
Evidence of All Privileged Users to Code Repository
Provide system screenshots or a system-generated list demonstrating which users have privileged access to your code repository.
Evidence of All Privileged Users to Deployment Tool
Provide system screenshots or a system-generated list demonstrating which users have privileged access to your deployment tool.
Additional Guidance
Privileged access to your application may be controlled by code repositories, backend systems, and/or frontend admin systems or portals.
Ensure that you have included all methods and users that are capable of making these changes.
Related Articles
Associated Unified Control ID | Associated Framework Control |
CTRL-9 | LCL-32 |