Service Account used by applications to access databases, run batch jobs or scripts, or provide access to other applications. These Privileged Identity usually have broad access to underlying company data Stores that resides in applications and databases. Passwords for these accounts are often embedded and stored in Plaintext files, a vulnerability that is replicated across multiple servers to provide greater fault tolerance for applications. This vulnerability represents a significant risk to an organizational Entity because the applications often host the exact data that Advanced Persistent Threats consider as an Item of Interest.
Service Account are a Non-person entity Digital Identity and may be shared
For example, if your Google Cloud Project employs server-to-server interactions such as those between a web application and Google Cloud Storage, then you need a Private Key and other Service Account credentials.
- based on information obtained 2017-08-16-