Glossary

Least privilege

Least privilege is the principle that every account — human or machine — should hold only the access its job requires, and nothing more. Auditors test it in nearly every framework: SOC 2, ISO 27001, HIPAA, and CMMC all expect access granted by role, reviewed on a schedule, and revoked when no longer needed.
Assemble Your GRC Team
Last updated July 26, 2026