Principle of Least Privilege



next up previous
Next: Separation of Duties Up: Role-Based Access Controls Previous: Centrally Administering Security

Principle of Least Privilege

The principle of least privilege has been described as important for meeting integrity objectives. [8] The principle of least privilege requires that a user be given no more privilege than necessary to perform a job. Ensuring least privilege requires identifying what the user's job is, determining the minimum set of privileges required to perform that job, and restricting the user to a domain with those privileges and nothing more. By denying to subjects transactions that are not necessary for the performance of their duties, those denied privileges cannot be used to circumvent the organizational security policy. Although the concept of least privilege currently exists within the context of the TCSEC, requirements restrict those privileges of the system administrator. Through the use of RBAC, enforced minimum privileges for general system users can be easily achieved.



next up previous
Next: Separation of Duties Up: Role-Based Access Controls Previous: Centrally Administering Security



John Barkley
Mon Jan 9 13:56:57 EST 1995