Need To Know: A principle in the control of access to confidential information. The concept suggests that information should be provided only to those individuals who absolutely need it to perform their responsibilities. The need-to-know principle helps to enforce the confidentiality of sensitive information, limit the number of people with access to this type of data, and reduce the risk of unauthorized disclosure or misuse of the information.
Categories: CC D3: Access Controls Concepts | CCSP D6: Legal - Risk and Compliance | CISM D1: Information Security governance | CISSP D5: Identity and Access Management (IAM) | Security+ D1: General Security Concepts | SSCP D1: Security Concepts and Practices
Related Articles:
- Glossary: Need to Know Determination
- Glossary: Disclosure Controls and Procedures
- Glossary: Classified
- CISSP D1 Preview | Risk Management Assessment – Part 1
- CISSP D1 Preview | The ISC² Code of Ethics
- CISSP Tips and Tricks | How to use practice questions, deconstruct them, and time management – Part 1
- CISSP D2 Preview | Data Remanence and Destruction
- CISSP Tips and Tricks | How to find your study materials – Free resources
- The Complete CISSP Bundle | Videos, Tests, PDF Guides, Flashcards, Glossary | ThorTeaches.comGet your Complete CISSP 2024 course: Videos, Practice questions, Flashcards, Glossary, Chatbot, PDF Study Guides | Get Certified with ThorTeaches.com
- US laws and burden of proof for the CISSP and CISM certifications