SECURITY / A CONCEPT NOTE

Least Privilege

the default should be 'no'

~65 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

The security principle that users, programs, and service roles should only be granted the minimum necessary permissions to perform their tasks, and nothing more.

02 / FOLLOW THE MECHANISM

How privilege is restricted

  1. Baseline deny

    new service account starts with zero permissions (default block).

  2. Audit run

    operator reviews requirements: this service only needs to write log files.

  3. Scope grant

    attaches a policy granting write-only access to log storage folder.

  4. Audit loop

    monitors permissions periodically, removing unused access codes.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · INCOMPLETE SKETCH

find unused permissions on an IAM role

aws iam generate-service-last-accessed-details --arn arn:aws:iam::...

The ellipsis omits required code or values. This sketch is not runnable as written.

Explore command anatomy in the CLI lab