Compliant (True), Limiting claims inside JWTs to unique identifiers or roles instead of full names and emails., Utilizing an Ingress controller configured with TLS certificates to secure local traffic via HTTPS., Mount sensitive configuration properties and database passwords as Kubernetes Secrets., Keeping temporary memory storages and logs completely clear of personal user data., Non-Compliant (False), Hardcoding plain text passwords or private keys inside container environment variables., Storing excess user demographic details inside the database just in case they are needed later., Recording complete API payloads containing personal names and locations inside debug logs., Treating ephemeral caches as permanent databases, making secure deletion processes difficult.

โดย

ลีดเดอร์บอร์ด

สไตล์ภาพ

ตัวเลือก

AI Enhanced: กิจกรรมนี้มีเนื้อหาที่สร้างโดย AI ศึกษาเพิ่มเติม

สลับแม่แบบ

คืนค่าการบันทึกอัตโนมัติ: ใช่ไหม