CISSP بالعربي | Masterclass #009 | D1 Ch5 | Security Principles: Least Privilege & Need to Know
Internetwork Technology
0:00 / 0:00
CISSP بالعربي | Masterclass #009 | D1 Ch5 | Security Principles: Least Privilege & Need to Know
335 просмотров · 7 дней назад
Internetwork Technology
326 подписчиков
335 просмотров · 7 дней назад
In this episode, we begin Domain 1 – Chapter 5: Security Principles and explore the foundational ideas that guide security decisions across the organization.
In the previous chapter, we studied Security Controls—the safeguards used to protect systems, networks, applications, and data.
Now we take one step back and ask:
What principles should guide the design and selection of those controls?
Security Principles are timeless, technology-agnostic guidelines that help organizations design stronger Security Architectures, make consistent decisions, and reduce Business Risk.
The key idea is:
Controls implement security. Principles guide security.
In this episode, we cover:
🔹 What Are Security Principles?
How principles guide Security Architecture and Security Controls
Why security must support Business Objectives
Consistent Security Decisions
Risk Reduction and Business Enablement
Security Principles vs Policies, Standards, and Controls
🔹 Principle #1: Least Privilege
Every user, application, process, or system should receive only the minimum permissions required to perform its assigned task—and nothing more.
We discuss:
Standard Accounts vs Privileged Accounts
Privilege Escalation
Privilege Creep
Just-in-Time Access
Privileged Access Management
Reducing the Blast Radius of compromised accounts
Least Privilege asks: What actions should this subject be allowed to perform?
🔹 Principle #2: Need to Know
Access to sensitive information should only be granted when there is a legitimate business need.
We explore examples involving:
HR and Salary Information
Customer and Payment Data
Project Documents
Medical and Classified Information
Data Classification and Compartmentalization
RBAC, ABAC, and IAM
We also explain why trust, seniority, or Security Clearance does not automatically provide access to all information.
Need to Know asks: Should this subject have access to this particular information?
Together, Least Privilege and Need to Know create a strong foundation for Access Control and Information Protection.
🔹 Think Like a Security Architect
Do not begin by asking:
“Which security product should we buy?”
Begin by asking:
What asset are we protecting?
Who needs access?
What actions do they need to perform?
What information do they need to see?
What Business Risk are we reducing?
The key mindset of this episode is:
Principles come first. Controls follow.
And remember:
We don’t sell products. We design protection.
🎓 Instructor
Mohamed Samir
Founder & CEO – InterNetwork Technology (INE)
Double CCIE #27042
Enterprise Network & Security Architect
#CISSP #CyberSecurity #SecurityPrinciples #LeastPrivilege #NeedToKnow #AccessControl #SecurityArchitecture #RiskManagement #InformationSecurity #CISSPArabic #BeyondCISSP #InterNetworkTechnology