Need to Know is a term that applies to sensitive and often classified information. It is a methodology used by government and defense contractor organizations dealing with highly sensitive and sometimes classified information. Under โNeed to Knowโ restrictions, a user must have official approval (security clearance, admin credentials) to access confidential or classified information. No-one is to be given knowledge of, possession, or access to sensitive โNeed-to-Knowโ information based upon their position, clearance level, or the office they represent.
While it may seem that โNeed to Knowโ applies only to government entities, SMBโs can use these their principles to protect the data. When setting up file permissions on your Human Resources directory, apply โNeed to Knowโ permissions and grant access based upon the individuals in HR that need such access and no-one else.
Train your employees on the principle of Need to Know and insider threats. Perhaps vigilant employees may be able to spot someone in your company behaving suspiciously who may ultimately turn out to be a malicious insider.
When having cell phone conversations, consider the topic youโre discussing and the location of your phone call. Ask yourself, do the people on this train, in line at this coffee shop, or at the local Walmart, need to know what Iโm taking about? Discretion may be appropriate.
Related Terms: Availability, Confidentiality, Integrity, Least Privilege
Source: Feynman, Richard (1997)
Discover and share the latest cybersecurity trends, tips and best practices โ alongside new threats to watch out for.
Stop tricking employees. Start training them. Take Control of Your Security Awareness Training with a Platform...
Read moreA recent discovery by cybersecurity firm Oligo Security has unveiled a series of critical vulnerabilities in...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.