home/dictionary/least privilege

least privilege

nounverified·updated Aug 28, 2026

The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources needed to perform its function.

Framework senses

SANS Glossary of Security Terms1 senseview framework →
§1
Least Privilege is the principle of allowing users or applications the least amount of permissions necessary to perform their intended function.
NIST Cybersecurity Framework1 senseview framework →
§1
The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
FFIEC Cybersecurity Assessment Tool, Baseline, May 20171 senseview framework →
§1
The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 22 sensesview framework →
§1
The security objective of granting users only those accesses they need to perform their official duties.
§2 · sense_2_pending_review
The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
NIST SP 800-121 senseview framework →
§1
The security objective of granting users only those accesses they need to perform their official duties.
Information Technology Laboratory Computer Security Resource Center Glossary1 senseview framework →
§1
The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
Sp 800-12. an introduction to computer security: The nist handbook.1 senseview framework →
§1
The security objective of granting users only those accesses they need to perform their official duties.
NIST SP 800-171r31 senseview framework →
§1 · glossary
The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources needed to perform its function.
Attribution from the CKI glossary mapping stage (glossary)
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
DR-088 backfill from the noun definition column