Перейти к содержимому

CISSP بالعربي | Masterclass #009 | D1 Ch5 | Security Principles: Least Privilege & Need to Know

Internetwork Technology

0:00 / 0:00

CISSP بالعربي | Masterclass #009 | D1 Ch5 | Security Principles: Least Privilege & Need to Know

335 просмотров · 7 дней назад
Internetwork Technology
326 подписчиков
335 просмотров · 7 дней назад
In this episode, we begin Domain 1 – Chapter 5: Security Principles and explore the foundational ideas that guide security decisions across the organization. In the previous chapter, we studied Security Controls—the safeguards used to protect systems, networks, applications, and data. Now we take one step back and ask: What principles should guide the design and selection of those controls? Security Principles are timeless, technology-agnostic guidelines that help organizations design stronger Security Architectures, make consistent decisions, and reduce Business Risk. The key idea is: Controls implement security. Principles guide security. In this episode, we cover: 🔹 What Are Security Principles? How principles guide Security Architecture and Security Controls Why security must support Business Objectives Consistent Security Decisions Risk Reduction and Business Enablement Security Principles vs Policies, Standards, and Controls 🔹 Principle #1: Least Privilege Every user, application, process, or system should receive only the minimum permissions required to perform its assigned task—and nothing more. We discuss: Standard Accounts vs Privileged Accounts Privilege Escalation Privilege Creep Just-in-Time Access Privileged Access Management Reducing the Blast Radius of compromised accounts Least Privilege asks: What actions should this subject be allowed to perform? 🔹 Principle #2: Need to Know Access to sensitive information should only be granted when there is a legitimate business need. We explore examples involving: HR and Salary Information Customer and Payment Data Project Documents Medical and Classified Information Data Classification and Compartmentalization RBAC, ABAC, and IAM We also explain why trust, seniority, or Security Clearance does not automatically provide access to all information. Need to Know asks: Should this subject have access to this particular information? Together, Least Privilege and Need to Know create a strong foundation for Access Control and Information Protection. 🔹 Think Like a Security Architect Do not begin by asking: “Which security product should we buy?” Begin by asking: What asset are we protecting? Who needs access? What actions do they need to perform? What information do they need to see? What Business Risk are we reducing? The key mindset of this episode is: Principles come first. Controls follow. And remember: We don’t sell products. We design protection. 🎓 Instructor Mohamed Samir Founder & CEO – InterNetwork Technology (INE) Double CCIE #27042 Enterprise Network & Security Architect #CISSP #CyberSecurity #SecurityPrinciples #LeastPrivilege #NeedToKnow #AccessControl #SecurityArchitecture #RiskManagement #InformationSecurity #CISSPArabic #BeyondCISSP #InterNetworkTechnology