ISC2 CISSP (Certified Information Systems Security Professional)Identity and Access Management (IAM)Medium

A security team is implementing logical access controls for a new enterprise resource planning (ERP) system. They want to ensure that users can only initiate transactions (e.g., 'create purchase order') and view reports relevant to their specific department and job function, without being able to modify system configurations or access sensitive HR data. Which principle of access control is being MOST directly applied?

  1. AAccountability
  2. BNeed-to-know
  3. CLeast privilege
  4. DSeparation of duties
Show answer & explanation

Correct answer: C. Least privilege

The scenario describes restricting users to only the *minimum* access necessary to perform their specific job functions ('only initiate transactions and view reports relevant to their department/job function', 'without being able to modify system configurations or access sensitive HR data'). This is the direct definition and application of the principle of least privilege.

Why the other options are wrong

  • A. Accountability ensures that actions can be traced back to an individual, which is important but not the principle governing *what* access they are granted.
  • B. Need-to-know is similar to least privilege but often refers more explicitly to access to classified or sensitive information, whereas least privilege is broader, covering all types of access rights.
  • D. Separation of duties prevents a single individual from completing a critical task end-to-end to prevent fraud, which is related but not the primary focus of limiting individual user access to minimum necessary functions.

Principle of Least Privilege

The principle of least privilege dictates that a subject should be granted only the minimum necessary rights or permissions to perform its duties.

  • Reduces the attack surface and potential damage from compromise.
  • Applies to users, processes, and applications.
  • A fundamental security best practice.

Memory trick: SLAN: Separation, Least, Accountability, Need.

More Identity and Access Management (IAM) questions