Skip to main content
Guidance

Device security principles for manufacturers

Principles to guide manufacturers in the design of secure, enterprise-connected devices.

Page 8 of 12

7. Minimise the privilege and reach of applications

Minimising each application’s privilege to a level that is only necessary for its function will minimise an attacker’s access to privileges if the application is compromised. In addition, capabilities such as virtualisation and sandboxing further prevent an application from compromising the broader system. Escalating privilege is a typical goal for attackers, who often need elevated levels of control to gain persistence in a network and to achieve their goals. Minimising privileges across applications will make this step more difficult for attackers.






Published

Reviewed

Version

2.1