SAMMY UI is optimized for resolutions with a width 1024px and higher.
V8.1.1
V8.1.1: Verify that authorization documentation defines rules for restricting function-level and data-specific access based on consumer permissions and resource attributes.
ASVS Maturity
V8.1.2
V8.1.2: Verify that authorization documentation defines rules for field-level access restrictions (both read and write) based on consumer permissions and resource attributes. Note that these rules might depend on other attribute values of the relevant data object, such as state or status.
ASVS Maturity
V8.1.3
V8.1.3: Verify that the application's documentation defines the environmental and contextual attributes (including but not limited to, time of day, user location, IP address, or device) that are used in the application to make security decisions, including those pertaining to authentication and authorization.
ASVS Maturity
V8.1.4
V8.1.4: Verify that authentication and authorization documentation defines how environmental and contextual factors are used in decision-making, in addition to function-level, data-specific, and field-level authorization. This should include the attributes evaluated, thresholds for risk, and actions taken (e.g., allow, challenge, deny, step-up authentication).
ASVS Maturity