Determinación
positiva por la que se confirma que un posible destinatario requiere el acceso
a, el conocimiento de, o la posesión de la información para desempeñar
servicios, tareas o cometidos oficiales.
Principio por
el cual se toma la determinación positiva de que un receptor tenga necesidad de
acceder a, conocimiento de, o posesión de información para llevar a cabo tareas
o servicios oficiales. [CCN-STIC-202:2006]
Es término
sinónimo de "mínimo privilegio". [Ribagorda:1997]
Principio de
seguridad por el que, para que una persona pueda acceder a una determinada
información clasificada, es necesario que ésta sea precisa para poder
desarrollar su trabajo, no siendo suficiente su puesto o rango. [CESID:1997]
A method of isolating
information resources based on a user’s need to have access to that resource in
order to perform their job but no more. The terms ‘need-to know” and “least
privilege” express the same idea. Need-to-know is generally applied to people,
while least privilege is generally applied to processes. [CNSSI_4009:2010]
Decision made by an
authorized holder of official information that a prospective recipient requires
access to specific official information to carry out official duties. [CNSSI_4009:2010]
(I) The necessity for access
to, knowledge of, or possession of specific information required to carry out
official duties. [RFC4949:2007]
A determination made by an
authorized holder of classified information that a prospective recipient has a
requirement for access to, knowledge, or possession of the classified
information to perform tasks or services essential to the fulfillment of a
classified contract or program. [DoD 5220:2006]
The principle according to
which a positive determination is made that a prospective recipient has a
requirement for access to, knowledge of, or possession of information in order
to perform official tasks or services. [CCN-STIC-401:2007]