2 cissp ® Official Study Guide Eighth Edition


Need-to-Know and Least Privilege



Download 19,3 Mb.
Pdf ko'rish
bet648/881
Sana08.04.2023
Hajmi19,3 Mb.
#925879
1   ...   644   645   646   647   648   649   650   651   ...   881
Bog'liq
(CISSP) Mike Chapple, James Michael Stewart, Darril Gibson - CISSP Official Study Guide-Sybex (2018)

Need-to-Know and Least Privilege
Need-to-know and the principle of least privilege are two standard principles followed in 
any secure IT environment. They help provide protection for valuable assets by limiting 
access to these assets. Though they are related and many people use the terms interchange-
ably, there is a distinctive difference between the two. Need-to-know focuses on permis-
sions and the ability to access information, whereas least privilege focuses on privileges.
Chapter 14, “Controlling and Monitoring Access,” compared permissions, rights, and 
privileges. As a reminder, permissions allow access to objects such as files. Rights refer to 
the ability to take actions. Access rights are synonymous with permissions, but rights can 
also refer to the ability to take action on a system, such as the right to change the system 
time. Privileges are the combination of both rights and permissions.


Applying Security Operations Concepts 
699
Need-to-Know Access 
The
need-to-know
principle imposes the requirement to grant users access only to data or 
resources they need to perform assigned work tasks. The primary purpose is to keep secret 
information secret. If you want to keep a secret, the best way is to tell no one. If you’re the 
only person who knows it, you can ensure that it remains a secret. If you tell a trusted friend, 
it might remain secret. Your trusted friend might tell someone else—such as another trusted 
friend. However, the risk of the secret leaking out to others increases as more and more peo-
ple learn it. Limit the people who know and you increase the chances of keeping it secret. 
Need-to-know is commonly associated with security clearances, such as a person having 
a Secret clearance. However, the clearance doesn’t automatically grant access to the data. As 
an example, imagine that Sally has a Secret clearance. This indicates that she is cleared to 
access Secret data. However, the clearance doesn’t automatically grant her access to all Secret 
data. Instead, administrators grant her access to only the Secret data she has a need-to-know 
for her job. 
Although need-to-know is most often associated with clearances used in military and 
government agencies, it can also apply in civilian organizations. For example, database 
administrators may need access to a database server to perform maintenance, but they don’t 
need access to all the data within the server’s databases. Restricting access based on a need-
to-know helps protect against unauthorized access resulting in a loss of confi dentiality.

Download 19,3 Mb.

Do'stlaringiz bilan baham:
1   ...   644   645   646   647   648   649   650   651   ...   881




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©hozir.org 2024
ma'muriyatiga murojaat qiling

kiriting | ro'yxatdan o'tish
    Bosh sahifa
юртда тантана
Боғда битган
Бугун юртда
Эшитганлар жилманглар
Эшитмадим деманглар
битган бодомлар
Yangiariq tumani
qitish marakazi
Raqamli texnologiyalar
ilishida muhokamadan
tasdiqqa tavsiya
tavsiya etilgan
iqtisodiyot kafedrasi
steiermarkischen landesregierung
asarlaringizni yuboring
o'zingizning asarlaringizni
Iltimos faqat
faqat o'zingizning
steierm rkischen
landesregierung fachabteilung
rkischen landesregierung
hamshira loyihasi
loyihasi mavsum
faolyatining oqibatlari
asosiy adabiyotlar
fakulteti ahborot
ahborot havfsizligi
havfsizligi kafedrasi
fanidan bo’yicha
fakulteti iqtisodiyot
boshqaruv fakulteti
chiqarishda boshqaruv
ishlab chiqarishda
iqtisodiyot fakultet
multiservis tarmoqlari
fanidan asosiy
Uzbek fanidan
mavzulari potok
asosidagi multiservis
'aliyyil a'ziym
billahil 'aliyyil
illaa billahil
quvvata illaa
falah' deganida
Kompyuter savodxonligi
bo’yicha mustaqil
'alal falah'
Hayya 'alal
'alas soloh
Hayya 'alas
mavsum boyicha


yuklab olish