Definition

principle of least privilege (POLP)

What is the principle of least privilege (POLP)?

The principle of least privilege (POLP) is the practice of limiting access to the minimal level that will allow normal functioning. Applied to employees, the principle of least privilege translates to giving people the lowest level of user rights that they can have and still do their jobs. The principle is also applied to things other than people, including programs and processes.

The principle of least privilege originated in the United States Department of Defense in the 1970s. The principle was designed to limit the potential damage of any security breach, whether accidental or malicious.

In a personal computing context, you can increase security by using an account without administrative rights. Operating in administrative mode can make your system vulnerable to malicious coding online that would be denied access if you were operating with lower permission levels. Some operating systems have least privilege built in. For example, Vista's user account control (UAC) has two operational modes, one with and one without administrative privileges. Even in the latter mode, however, explicit permission is required for external system access.

A related concept, privilege bracketing, involves ensuring that when permission levels must be raised temporarily that the higher level is in effect for the briefest possible time. So, for example, you might log on to an administrative account when necessary for some task and immediately revert to a lower-level account as soon as that task is complete.

The principle of least privilege is also known as the principle of least authority (POLA).

This was last updated in September 2008
Posted by: Margaret Rouse

Email Alerts

Register now to receive SearchSecurity.com-related news, tips and more, delivered to your inbox.
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Do you have something to add to this definition? Let us know.

Send your comments to techterms@whatis.com

There are Comments. Add yours.

 
TIP: Want to include a code block in your comment? Use <pre> or <code> tags around the desired text. Ex: <code>insert code</code>

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy
Sort by: OldestNewest

Forgot Password?

No problem! Submit your e-mail address below. We'll send you an email containing your password.

Your password has been sent to: