Glossary

Least Privilege

Security principle where users receive only minimally necessary access rights for their function.

A

B

C

D

E

F

G

H

I

J

K

L

The principle of least privilege dictates that users, applications, and processes should be granted only the minimum level of access necessary to perform their designated functions. This fundamental security concept reduces the attack surface by limiting what a compromised account or malicious insider can access, thereby containing the potential blast radius of a security incident.

Implementing least privilege requires regular access reviews, role-based access control (RBAC), and timely deprovisioning when roles change. It is a cornerstone requirement across frameworks such as ISO 27001, NIS2, and SOC 2, and works in conjunction with privileged access management to ensure that elevated permissions are tightly controlled and monitored.

M

N

O

P

Q

R

S

T

U

V

W

Z