SA-8(14) - Security and Privacy Engineering Principles | Least Privilege

Implement the security design principle of least privilege in [Assignment: organization-defined systems or system components].


ID: SA-8(14)
Enhancement of : SA-8

Space Segment Guidance

Some capabilities need activation only in specific modes or maintenance windows. Consider remotely enabling them with explicit scopes (time-bounded, pass-bounded, mode-bounded), auditing both enable and disable events, and auto-reverting to nominal if a window expires or a reset occurs. Telemetry that confirms deactivation, and that disabled state survives reboot/SEU, helps avoid lingering elevated capability.