...
ENV00-J. Do not sign code that performs only unprivileged operations
ENV07-J. Do not deploy an application that can be accessed by the JVM Tool Interface
ENV09-J. Limit remote uses of JVM Monitoring and Managing
ENV01-J. Place all privileged code in a single package and seal the package
...
ENV05-J. Do not grant RuntimePermission with target createClassLoaderENV34-J. Do not disable bytecode verification
ENV06-J. Provide a trusted environment and sanitize all inputs
ENV07-J. Do not deploy an application that can be accessed by the JVM Tool Interface
ENV09-J. Limit remote uses of JVM Monitoring and Managing
ENV34-J. Do not disable bytecode verification
Risk Assessment Summary
Recommendations
...