Least Privilege

Kind: principle

Layer: Security Core

Aliases: Principle of Least Privilege, PoLP

Record: architecture:least-privilege

Severity: mandatory

Scope: user, service, process, data

Canonical: Ontology

A design rule that each user, service and process holds only the permissions its task needs.

Listed in Architecture principles, after Defense in Depth and before Zero Trust Architecture.

Requires

Reinforces

Enables

Conflicts with

In tension with

Tensions

Contracts

Violated by

Refactored by

Severity

Category

Reinforced by

Linked from