Need to Know Determination: The “Need to Know Determination” is the process by which organizations assess and decide which individuals need access to specific information to fulfill their job duties. It’s an aspect of access control focused on minimizing the risk of unauthorized information disclosure by granting access only to those with a justified requirement for that information.
Categories: CC D3: Access Controls Concepts | CCSP D6: Legal - Risk and Compliance | CISM D1: Information Security governance | CISSP D5: Identity and Access Management (IAM) | Security+ D1: General Security Concepts | SSCP D1: Security Concepts and Practices
« Back to Glossary Index