...By using Type Enforecment technology to confine each process to a specific cell, SecureOS enforces what security engineerscall the principle of least privilege, which mandates that each process should have access to those resources...
http://www.clue.ch/uploads/media/SecureOS_Type_Enforcement.pdf