ISC2 Certified in Cybersecurity (CC)Access Controls ConceptsEasy

A system administrator is configuring access to a new financial reporting application. The policy states that users should only be able to access the specific reports required for their job function, and nothing more. This approach directly aligns with which access control principle?

  1. ANeed-to-Know
  2. BAccountability
  3. CSeparation of Duties
  4. DImplicit Deny
Show answer & explanation

Correct answer: A. Need-to-Know

The 'Need-to-Know' principle dictates that access to information should be granted only when it is essential for an individual to perform their assigned duties. This directly matches the scenario where users access only specific reports required for their job function.

Why the other options are wrong

  • B. Accountability ensures that actions can be traced to an individual; it doesn't define the scope of access itself.
  • C. Separation of Duties prevents a single individual from controlling an entire critical process; it doesn't directly address limiting access to only necessary information.
  • D. Implicit Deny is a rule that states anything not explicitly permitted is denied; while related to security, it's a mechanism, not the guiding principle described.

Need-to-Know

A security principle stipulating that individuals should only have access to information or resources that are essential for them to perform their assigned job functions.

  • Limits access to the bare minimum required for a task.
  • Reduces the risk of unauthorized disclosure.
  • Often implemented alongside Least Privilege.

Memory trick: Only open the report you NEED to KNOW for your job.

More Access Controls Concepts questions