least privilege
nounid
3126·updated Aug 28, 2026verified
The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources needed to perform its function.
MWE
Attested in
NIST SP 800-171 Rev 3 - Protecting CUI in Nonfederal Systems
03.01.0503.01.05.d ¶ 103.01.05.d ¶ 103.01.0603.01.073.2.2 ¶ 89
Classifications
Entity Type
Control100%manual reviewaxis_review_queue.v1
Sensitivity
—85%llm-generatedllm:claude-haiku-4-5
Information Class
—90%llm-generatedllm:claude-haiku-4-5
Variants
- synonym
- sufficient access
- alternatephrasing
- Least Privilege
- plural
- least privileges
- possessive
- least privilege's
- pluralpossessive
- least privileges'
Framework definitions
- §1
- Least Privilege is the principle of allowing users or applications the least amount of permissions necessary to perform their intended function.
- §1
- The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
- §1
- The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
- §1
- The security objective of granting users only those accesses they need to perform their official duties.
- §2 · sense_2_pending_review
- The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
- §1
- The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
- §1
- The security objective of granting users only those accesses they need to perform their official duties.
- §1
- The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.
- §1
- The security objective of granting users only those accesses they need to perform their official duties.
- §1 · glossary
- The principle that a security architecture is designed so that each entity is granted the minimum system authorizations and resources needed to perform its function.Attribution from the CKI glossary mapping stage (glossary)
- §1 · legacy_primary
- The principle that a security architecture should be designed so that each entity is granted the minimum system resources and authorizations that the entity needs to perform its function.DR-088 backfill from the noun definition column
Outgoing relationships
No outgoing triples
This term is not the subject of any RDF-style relationship yet.
Incoming relationships
No incoming triples
No other term currently asserts a relationship to this one.