The organization utilizes the principle of least functionality in deploying and configuring systems. Systems must not have rights to anything that is not needed to accomplish what they are intended for.
See an example process description from task's page
Connected other frameworks and requirements:
PR.PT-3: Principle of least functionality
NIST CSF
9.3 (MIL2): Implement IT and OT Asset Security as an Element of the Cybersecurity Architecture