Jerome Saltzer
- Co-authored The Protection of Information in Computer Systems (1975) with Michael Schroeder
- Defined least privilege, fail-safe defaults, complete mediation, and psychological acceptability
- Worked on Multics and MIT's Project Athena
Bio
Jerome Saltzer, professor emeritus at MIT, co-authored the 1975 paper "The Protection of Information in Computer Systems" with Michael Schroeder. Its list of design principles, least privilege, fail-safe defaults, complete mediation, economy of mechanism, separation of privilege, least common mechanism, open design, and psychological acceptability, is still the checklist the field measures itself against. He also worked on Multics and MIT's Project Athena, which produced Kerberos.
Profile built from public academic and publication records.
Where their work shows up
Least privilege is the reason privileged access management and access reviews exist as practices rather than opinions. Psychological acceptability is the principle the industry ignored for thirty years of password complexity rules, and the one that passkeys finally satisfy: the secure path has to be the easy one, or users will route around it. Fifty years on, most identity failures still map to one of these eight principles.
Related on Start with Identity
- GlossaryCIEM
Cloud Infrastructure Entitlement Management. Tools that discover and right-size identities and permissions across AWS, Azure, and GCP, reducing excessive and un
- GlossaryEntitlement
A specific permission or right an identity holds over a resource. Governance and CIEM exist to keep entitlements understood, justified, and minimal. Entitlement
- GlossaryPrivilege Escalation
Gaining higher access than originally granted, by exploiting misconfigurations, vulnerabilities, or over-permissioned identities. Tightly linked to privileged a
- ExpertCo-author of the Needham-Schroeder protocol
Michael D. Schroeder co-authored two of the foundational papers in this field within three years of each other: the 1975 design-principles paper with Jerome Sal
- ExpertCo-author of the NIST RBAC model
David Ferraiolo co-authored "Role-Based Access Controls" with Rick Kuhn, presented at the 15th National Computer Security Conference in October 1992. The NIST m
- ExpertCo-author of the NIST RBAC model
Rick Kuhn co-authored the 1992 NIST paper on role-based access control with David Ferraiolo and has worked on the model, its formalization, and its assurance ev