This objective ensures that even authorized users only have access to the specific actions and data they need to do their jobs—nothing more. This supports the principle of least privilege.
👉 This aligns with NIST SP 800-171 Rev. 2 Control 3.1.1 and reinforces Role-Based Access Control (RBAC) expectations.