Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Discuss/Define: Ensure Least Privileged Access #22

Open
jischr opened this issue Dec 16, 2024 · 1 comment
Open

Discuss/Define: Ensure Least Privileged Access #22

jischr opened this issue Dec 16, 2024 · 1 comment

Comments

@jischr
Copy link

jischr commented Dec 16, 2024

topics to cover:

  • ensure end users only have access to what they need in my application at any given point in time
@dhs-BI
Copy link
Contributor

dhs-BI commented Jan 7, 2025

@jischr how would we profile this? Enforcing least privilege is a pattern, but I don't see a clear path to standardization of the pattern since it depends heavily on the business rules being enforced.

Does this require an implementer to be able to implement and enforce a zero standing privileges model?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants