E. of Spoofing
We cannot tell which of our admins edited personal data, as admin accounts are shared.
Threat |
|
Your administrators are using the same login credentials, perhaps to save on paying for extra licenses. This isn’t a good practice because it gives plausible deniability in the event that they perform some accidental or nefarious action. |
|
CAPEC |
CAPEC-560 - Use of Known Domain Credentials CAPEC-653 - Use of Known Operating System Credentials |
ASVS |
2.5.4 - Ensure shared or default accounts have been removed 2.10.1 - Ensure services are not authenticating with shared accounts |
CWE |
N/A |
Mitigations |
|
... |