Had to do some Sharepoint security troubleshooting today…. this article is a good recap of the security model in Sharepoint.
As a site owner, when you create the permission structure for your site or grouping of sites, you should balance ease of administration with the need to control specific permissions for individual securable objects. With any Web site, it is also important to follow the principle of least privilege when authorizing access to the site.
About controlling access to sites and site content - SharePoint Server - Microsoft Office Online