Rule number 1: Don't mess with security unless you know what you're doing.
Rule number 2: Good security is layered security.
Rule number 3: Incorporate security planning into your governance plan. Identify who has what roles and responsibilities and how changes will be administered. Consider who can create sites, terms, lists and other SharePoint elements.
Takeaway: Don't mess with security unless you know what you're doing.
Share