It’s time to restrict user rights

Most of the best ideas in IT security – indeed, security in general – have been around for a long time. One that is all too often forgotten is the concept of “least privilege”, or using the bare minimum level of access to get the job done.

For example, everyday tasks such as reading email or browsing the web don’t need the same amount of system access as less common tasks like installing a printer. Although you need to write to the data areas on the disk, there should be no need to install device drivers, modify system settings, and so on. Users running with extra rights are a prime target for malicious software that takes full advantage of the extra rights.

Although sound in principle, the devil is in the details. Often, application developers assume blindly they can do anything and seldom seem to trap for the inevitable “access denied”. Indeed, in many cases, systems are simply set up with a single user that has administrator rights, and the user is none the wiser.

You must be a registered member to access this content.
Please Sign in below or Register now.
NOTE: This Feature is more than 7 days old.
Please login to view the rest of this article

Login above or Register now and get unlimited access.

Already subscribed but have forgotten your login? Recover your password your here.


Why sign up?
  • Unlimited access to SC Magazine content as well as access to to our global resources from SC Magazine US and UK editions.
  • Full use of over 11,000 articles database covering breaking news, video interviews, case studies, research, product reviews and exclusive features with fast and intuitive filtering of results.
  • Personalised "Recommended for you" filters to ensure you have the most relevant content at your finger tips.
  • Daily security bulletin direct to your inbox covering the latest security news from Australia/NZ and around the world.

Register now, its free! We'll never sell your details to third parties and it helps SC Magazine to keep serving you quality stories.
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read