home/dictionary/need to know

need to know

nouncandidate·updated May 12, 2026

An administrative action officially declaring a particular individual requires access to specified sensitive or classified information in order to perform their assigned duties.

Framework senses

NERC CIP-003-6 (Security Management Controls) v61 senseview framework →
§1
An administrative action officially declaring a particular individual requires access to specified sensitive or classified information in order to perform their assigned duties.
NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
A method of isolating information resources based on a user’s need to have access to that resource in order to perform their job but no more. The terms ‘need-to know” and “least privilege” express the same idea. Need-to-know is generally applied to people, while least privilege is generally applied to processes.
CNSSI-4009 (Glossary of Information Assurance Terms)1 senseview framework →
§1
A method of isolating information resources based on a user’s need to have access to that resource in order to perform their job but no more. The terms ‘need-to know” and “least privilege” express the same idea. Need-to-know is generally applied to people, while least privilege is generally applied to processes.