Fork me on GitHub

BuildAndDeployment -> Deployment: Environment depending configuration parameters

Risk and Opportunity

Risk: Attackers who compromise source code can see confidential access information like database credentials.
Opportunity: Configuration parameters are set for each environment not in the source code.

Usefulness and Requirements of this Activitiy

Usefullness: High
Required knowledge: Low (one discipline)
Required time: Low
Required resources (systems): Very Low

Additional Information

ISO27001 2017

samm

OWASP SAMM VERSION 2