Which security principle defines the minimum information or access required for a given job or function?

Study for the CompTIA SecurityX Test. Equip yourself with comprehensive flashcards and multiple choice questions that include hints and explanations. Gear up for your certification exam!

Multiple Choice

Which security principle defines the minimum information or access required for a given job or function?

Need to Know is the principle that access to information is granted only when it is necessary to perform the duties of a person’s role. This keeps sensitive data and specific resources accessible only to those who truly need them for their task, reducing exposure if credentials are compromised or if a person’s role changes. The idea is to minimize who sees what data, not just what actions they can perform.

Least Privilege focuses on restricting system rights and permissions to the smallest set needed to perform tasks, which is related but centers on what a user can do in a system rather than the specific information they can access. Separation of Duties is about splitting critical tasks so no single person can complete a process alone, helping prevent fraud. Defense in Depth is a layered approach to security, adding multiple controls across different points in the system.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy