What is the principle of least privilege and how does it apply to the Protect function?
- A.Giving administrators all possible permissions, since facility power and HVAC resilience are outside the Framework's PROTECT outcomes; in addition, Tiers apply to vendors only, while internal operations are measured by Profiles
- B.Allowing all users equal access to all systems
- C.Removing all privileges from standard users, proceeding as though least privilege is a Detect outcome and resilience requirements were moved out of Protect and into the Respond function
- D.Granting users, processes, and systems only the minimum access permissions necessary to perform their functions, reducing the potential impact of compromised accounts or insider threats
Why D is correct
Least privilege limits access to what is strictly necessary, reducing the attack surface and potential damage from compromised accounts, malware, or insider threats.
Know someone studying for NIST CSF? Send them this one.