Individual are granted enough privilege to accomplish assigned tasks, but no more.
This principle is applied in direct proportion and with increased rigor as the potential for damage rises.
Firewall users and administrators are segmented into small groups, each with a well-defined role and access restricted to group-specific data and capabilities.

