home/glossary/Principle of least privilege

Principle of least privilege

nounid 3655·updated Aug 30, 2026
verified· unreviewed

The security objective of granting users only the access needed to perform official duties.

MWE

Attested in

NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems1 citation · 1 machine-matched · observed 2026-09-01 under anchor/0.9/36451/2026-09-01
03.01.05.d ¶ 1

Classifications

Entity Type

Requirement0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

85%llm-generatedllm:claude-haiku-4-5

Information Class

90%llm-generatedllm:claude-haiku-4-5

Variants

plural
Principle of least privileges
possessive
Principle of least privilege's
pluralpossessive
Principle of least privileges'

Framework definitions

Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary1 senseview framework →
§1
The security objective of granting users only the access needed to perform official duties.
NIST SP 800-171r31 senseview framework →
§1 · attested_usage_pack_match
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
The security objective of granting users only the access needed to perform official duties.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.