Public services need security and broad access. Include older devices, accessibility and account recovery in protection acceptance.
Evaluation approach
Separate identity changes, submissions and general information by risk. Use RASP context for critical actions while retaining server authentication and authorization. Unsupported devices and attack signals are different conditions.
Application example
If a user is blocked during an application process, preserve drafts and identify unfinished steps. Alternative channels should retain the required assurance, and support should use a helpful event code.
Limits and considerations
Enabled accessibility services are not evidence of malicious intent. Test legitimate assistive technology before broad restrictions.
Checks and decisions
- Preserve transaction state
- Test accessibility journeys
- Provide support and alternative channels
Monitor effects across device groups and investigate concentrated blocks.
Sources
The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.