Applications

Organizations use applications to perform tasks and must manage user access and data to ensure security and compliance.

2 slides · 1 min read · Domain 5

Slide 1

Every organization uses applications. Whether we pay a use-license for them or build our own applications, we need to protect them. Applications are part of the organization's asset inventory, and in many cases these applications contain data that is important for the organization.

We must ensure access and use of the application is performed in accordance with access control (AC) principles.

Even if we look at applications used by the

In contrast, there are applications that are only used by designated people in the entire organization, not every employee needs access to the same resources and organization, and thus most employees at the same permission level. For example, will not require access to them. For if an organization uses Microsoft 365, it example, an accounting application will is reasonable to assume all users have only be used by finance and designated access to their email and SharePoint folder.

managers in the company, and software However, in SharePoint they should have development tools might be widely used access only to those folders required to by the research and development (R&D) do their job (following the least privilege department, but sales and finance do not principle), and not all employees are granted need access to these tools. access to additional resources such as business analytics tools or development tools.

Test this domain