SSCP Systems Security Certified PractitionerAccess ControlsMedium

A software development team is building a new application that needs to securely access a database containing customer personal identifiable information (PII). The security policy dictates that the application should only be able to retrieve the specific PII fields absolutely necessary for its function (e.g., name and email, but not home address or phone number) and only when a specific, authorized request is made. This principle aims to minimize the potential impact of a data breach. Which security principle is being applied?

  1. ANeed-to-Know
  2. BDefense in Depth
  3. CLeast Privilege
  4. DSeparation of Duties
Show answer & explanation

Correct answer: A. Need-to-Know

The 'need-to-know' principle dictates that access to information should be granted only when it is essential for an individual or system to perform their assigned tasks. The scenario explicitly states the application should only retrieve 'specific PII fields absolutely necessary for its function', which directly aligns with this principle.

Why the other options are wrong

  • B. Defense in depth uses multiple layers of security, which is a broader strategy, not a specific access principle for data fields.
  • C. Least privilege grants only the minimum permissions required to perform a task, which is related but 'need-to-know' is more specific to data access.
  • D. Separation of duties divides critical tasks among multiple individuals to prevent fraud or error, which is not described here.

Need-to-Know

A security principle that restricts access to information to only those individuals or systems whose jobs require them to have that access.

  • A refinement of the principle of least privilege.
  • Focuses on limiting access to specific data or information.
  • Crucial for protecting sensitive and classified information.

Memory trick: Need-to-Know: Only see what you absolutely must to do your job, nothing more.

More Access Controls questions