Access Control Models-1
Access Control Models-1
• The principle of least privilege specifies a limited, as-needed approach to granting user and
process access rights to specific information and tools. Access rights should be time-based
to limit the resource's access to only the time that is needed to complete necessary tasks.
Granting access beyond this scope increases the potential for malicious manipulation of
sensitive data or processes by unauthorized actors. The assigning of access rights limits
system-damaging attacks from users, regardless of whether they are intentional. All users
must be authenticated and authorized, and should only be authorized at the lowest privilege
level required to perform their functions.
• Separation of duties is the concept of having more than one person who is required to
complete a task. Separation of duties is an internal control to prevent fraud and error.