Least privilege: A computer security concept in which a user or program is given the minimum levels of access necessary to complete its tasks. This means granting only the rights or permissions necessary to perform an assigned job function, and no more. This approach helps limit the potential damage that can result from errors, system faults, or unauthorized use of privileges, making it a fundamental strategy for maintaining system security.
Categories: CC D3: Access Controls Concepts | CCSP D5: Cloud Security Operations | CISM D3: Information Security Program | CISSP D5: Identity and Access Management (IAM) | Security+ D1: General Security Concepts | SSCP D1: Security Concepts and Practices
Related Articles:
- Glossary: Security Design
- Glossary: Protection philosophy
- Glossary: Permission Aggregation
- Glossary: OS hardening
- Glossary: Compartmented Mode
- The Complete CISSP Bundle | Videos, Tests, PDF Guides, Flashcards, Glossary | ThorTeaches.comGet your Complete CISSP 2024 course: Videos, Practice questions, Flashcards, Glossary, Chatbot, PDF Study Guides | Get Certified with ThorTeaches.com
- CISSP certification: Need to know and least privilege.
- CISSP certification: Access Control Defensive Categories and Types:
- CISSP – Need to know, least privilege and objects/subjects.
- CISSP – the CIA Triad – Confidentiality!