An accidentally disclosed SAS token with excessive privileges enabled researchers to access nearly 40TB of Microsoft’s data, highlighting the risks of privilege mismanagement and oversharing.
For all the criticism it gets, this is something that Common Criteria at EAL 3 and higher covers, and if your company can’t ensure secure development of a product, the product doesn’t get certified. At least my scheme is always very strict with life cycle aspects, and if you’re not getting a certificate for a market it’s required in, that’s money lost, and a huge motivator for management to implement changes.
For all the criticism it gets, this is something that Common Criteria at EAL 3 and higher covers, and if your company can’t ensure secure development of a product, the product doesn’t get certified. At least my scheme is always very strict with life cycle aspects, and if you’re not getting a certificate for a market it’s required in, that’s money lost, and a huge motivator for management to implement changes.