Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

Principle of least privilege

Also known as: Least privilege principle, POLP

German: Prinzip der minimalen Rechte (Least Privilege)

In information security, the principle of least privilege is the design rule that every user, program and process should operate with the minimum set of privileges necessary to perform its function, for no longer than necessary, so that errors and compromises cause as little damage as possible.

  • OT security

In one sentence

The principle of least privilege says every user, program and process should have only the minimum privileges needed, for no longer than needed.

Example

Following the principle of least privilege, the recipe download service runs under its own account that may write recipe data blocks but cannot change the PLC program.

Explained in context

Context cards connect this term with others to answer one question. Also in British English and German.

How it applies

  • Engineering: The principle guides role design, service account configuration, network rules (only necessary flows) and software architecture (components run without administrator rights). IEC 62443 applies it in its use control requirements.
  • Product development: Products should support fine-grained roles so that operators can apply the principle; a device with only one all-powerful account makes it impossible.
  • Operation: "For no longer than necessary" matters as much as "no more than necessary": elevated rights for a maintenance task should be granted just in time and removed afterward.
  • Documentation: Security guidelines should recommend role assignments and warn about functions that need elevated rights. Instructions should tell readers which role a task requires, instead of assuming administrator access.

Principle of least privilege vs. least-privilege access

The principle is the rule. Least-privilege access is the configured state of a concrete system that follows it. An audit checks the latter against the former.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: AI TechDoc Blog editorial definition, based on information security practice (Saltzer and Schroeder) and IEC 62443

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!