least privilege
Term · Cybersecurity · MLC-T-CYB-002450
1. A security principle that a system should restrict the access privileges of users (or processes acting on behalf of users) to the minimum necessary to accomplish assigned tasks.
2. The principle that a security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
3. The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources needed to perform its function.
| Identifier | MLC-T-CYB-002450 |
|---|---|
| Field | Cybersecurity |
| References | CNSSI 4009-2022; NIST SP 800-12 Rev. 1; NIST SP 800-53 Rev. 5 from CNSSI 4009-2022; NIST SP 800-171r3; NIST CSRC Glossary |
Record as JSON
{
"id": "MLC-T-CYB-002450",
"term": "least privilege",
"field": "Cybersecurity",
"definition": "1. A security principle that a system should restrict the access privileges of users (or processes acting on behalf of users) to the minimum necessary to accomplish assigned tasks.\n\n2. The principle that a security architecture is designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.\n\n3. The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources needed to perform its function.",
"references": [
"CNSSI 4009-2022; NIST SP 800-12 Rev. 1",
"NIST SP 800-53 Rev. 5 from CNSSI 4009-2022",
"NIST SP 800-171r3",
"NIST CSRC Glossary"
],
"url": "https://mlchart.com/terminology/cybersecurity/least-privilege/"
}
Record 2,450 of 4,693 in Cybersecurity terminology (MLC-0102). Request the full dataset.