Glossary term

Principle of Least Privilege

Every account, process and token receives only the minimum permissions required for its task, for the minimum time required, and no more.

Browse the glossary →

Related entries

More glossary terms

Multi-Factor Authentication (MFA)
Requiring two or more independent factors, something you know, have and are, so a stolen password alone cannot grant access to an account.
Patch Management
The process of identifying, testing and deploying updates across an estate on a defined schedule, with exceptions tracked rather than silently skipped...
Attack Surface
The total set of points where an unauthorised user can attempt to enter or extract data: exposed ports, endpoints, features, credentials and physical...
CVE
Common Vulnerabilities and Exposures. A public identifier such as CVE-2021-44228 assigned to a specific vulnerability, giving everyone one unambiguous...
CWE
Common Weakness Enumeration. A catalogue of the underlying defect class, for example CWE-89 for SQL injection, independent of any particular product o...
← Back to glossary

We use only the cookies needed to run this site — your session, your sign-in state and CSRF protection. There are no advertising or analytics trackers. How cookies are used