ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsMedium

A government agency is updating its security protocols for accessing classified information. Their new policy states that all employees must only be granted access to the absolute minimum information and resources required to perform their specific job functions. Any access beyond this is strictly prohibited. Which access control principle is being enforced here?

  1. AImplicit Deny
  2. BJob Rotation
  3. CSeparation of Duties
  4. DNeed-to-Know
Show answer & explanation

Correct answer: D. Need-to-Know

The 'Need-to-Know' principle dictates that individuals should only have access to the specific information necessary to perform their assigned duties. This is a crucial aspect of protecting classified or highly sensitive data, ensuring that even if someone has a general security clearance, they only see what is essential for their current task.

Why the other options are wrong

  • A. Implicit Deny is a rule that states if access is not explicitly granted, it is denied; it's a mechanism, not a principle for information access.
  • B. Job Rotation involves changing employee responsibilities periodically to prevent fraud and cross-train.
  • C. Separation of Duties divides critical tasks among multiple people, not about minimum information access.

Need-to-Know

An access control principle stating that an individual should only be granted access to the specific information and resources absolutely required for their assigned duties.

  • A refinement of the 'Least Privilege' principle
  • Crucial for protecting classified or sensitive data
  • Limits exposure of information even to authorized personnel

Memory trick: Need-to-Know: 'If you don't need to know, you won't know.'

More Access Controls Concepts questions