Least Privilege

Assign minimum necessary rights to a subject that requests access to a resource, minimize allowable access time relinquish privileges. Granting user permissions beyond necessary rights of an action can allow that user to obtain or change information in unwanted ways. Careful delegation of access rights can limit attackers from damaging a system.

