Least privilege
Limit access according to approved role, scope, and duration.
ICSInternational Cyber SecurityA high-level view of security responsibilities and operating principles used when delivering ICS services.


Use these areas to confirm fit, dependencies, ownership, and the evidence required for acceptance.
Limit access according to approved role, scope, and duration.
Keep delivery activity within the authorized systems and data boundary.
Record relevant configuration, approval, testing, and handover.
Route issues according to affected service, data, and decision authority.
Contact ICS when your procurement or security team requires controlled documentation.

Make data responsibility explicit before access or processing begins.

Protect users and systems while enabling timely technical investigation.

Send the right evidence to the right reviewer without exposing sensitive implementation detail unnecessarily.
A high-level view of security responsibilities and operating principles used when delivering ICS services.
Discuss this scope