R094. Specify rules in declarative mood

Requirement

Access control rules must be specified in declarative mood instead of pragmatic mood.

References

  1. HIPAA Security Rules 164.312(c)(1): Integrity: Implement policies and procedures to protect electronic protected health information from improper alteration or destruction.

Copyright © 2021 Fluid Attacks, We hack your software. All rights reserved.