Least Privilege
The principle of granting identities and processes only the permissions required for their current task and no broader authority.
Security Context
Least privilege limits identities and processes to the authority required for their current work. Database roles, filesystem permissions, container capabilities, and IAM policies all use this principle to reduce blast radius when an account or component fails or is compromised.
Availability Boundary
Least privilege does not mean zero privilege. Removing permissions that are genuinely required creates availability and operational failures, while privilege creep over time requires periodic review.
Related Security Concepts
- Zero Trust
- Attack Surface
- Defense in Depth
- Authorization