dcsimg
Main » TERM » L »

Least Privilege Access Definition & Meaning

Least privilege access is the principle of limiting employees' access to only the accounts, documents, and data that they must have to do their job properly. Permitting employees to access high-level accounts that they don't need to enter, whether intentionally or accidentally, can cause companies a barrage of problems, including occupational fraud. Implementing a least privilege strategy forces a business to be more aware of each employee's specific job details and needs: which accounts and files does this person access on a daily basis? Least privilege strategies help businesses manage who is accessing sensitive information with greater caution and focus.

Employees who don't have enough security training are susceptible to social engineering tactics such as email phishing. If they have access to finances they shouldn't, an attacker could trick them into sending company resources or credentials, costing the company thousands or millions of dollars. Small security mistakes can lead to a wealth of problems. Limiting access to applications and finances can decrease the likelihood of such a breach.

Privileged access management

Many large data breaches suffered by companies come through privileged access accounts, or high-level accounts that system administrators and executive employees can access. Privileged access management (PAM) combats this by significantly reducing the account privileges of employees within an organization. Sensitive information such as passwords, databases, and encryption keys are just a few examples of company data that PAM should restrict. Accounts that may need to be restricted include domain administrative accounts, which allow users to add and edit other users within company systems, and application accounts, which allow users to make changes to company applications and software.

Some governing bodies are even imposing least privilege regulations on companies, knowing that data breaches are an enormous liability. Businesses may be forced to comply with certain privilege access requirements if they don't implement PAM strategies on their own.

Zero trust

A zero trust architecture is not exactly the same as least privilege access: it uses the least privilege principle as just one of its features. Zero trust architecture requires strict authentication even for accounts and networks that users are allowed to access. Zero trust asks users to verify their credentials for every account, application, or network they ask to enter.

Both least privilege and zero trust principles attempt to limit the ways attackers can access sensitive data. As workspaces are forced to take greater security measures, either or both may be required for minimum compliance with data protection regulations.










LATEST ARTICLES
Texting & Chat Abbreviations

From A3 to ZZZ we list 1,559 text message and online chat abbreviations to help you translate and understand today's texting lingo. Includes Top... Read More »

Huge List of Computer Certifications

Have you heard about a computer certification program but can't figure out if it's right for you? Use this handy list to help you decide. Read More »

STUDY GUIDES
Computer Architecture Study Guide

Computer architecture provides an introduction to system design basics for most computer science students. Read More »

Network Fundamentals Study Guide

Networking fundamentals teaches the building blocks of modern network design. Learn different types of networks, concepts, architecture and... Read More »

The Five Generations of Computers

Learn about each of the five generations of computers and major technology developments that have led to the computing devices that we use... Read More »