Least privilege
People and services receive only the access required for their role.
Security controls are most useful when they match the system’s users, information and risks and can be maintained after launch.
People and services receive only the access required for their role.
New users, features and environments begin in a controlled state.
Identity, application, data and infrastructure controls work together.
Important actions and changes are recorded proportionately to operational need.
The platform collects, exposes and retains only the information required.
Failure, backup, restoration and operational ownership are considered during design.
Work may include a permissions matrix, sensitive-data inventory, threat scenarios, logging requirements, backup and recovery decisions, and ownership of security-related changes.
No platform or control can guarantee complete protection. Priorities should be based on the system’s likely threats, impact and operating context.
Make access, data and recovery decisions visible early.