Which operational security principle decreases the likelihood that an external adversary will obtain critical system information by allowing access only to personnel whose duties require it?
The need-to-know principle limits disclosure of sensitive details to the smallest possible group whose job functions require that knowledge. By shrinking the insider pool, it minimizes the number of potential targets an adversary can exploit, thereby protecting mission-critical information. High availability, obfuscation, and redundancy do not inherently restrict access and therefore do not serve this counterintelligence purpose.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why does limiting access to a small group improve security?
Open an interactive chat with Bash
What other countermeasures can help prevent data exposure?
Open an interactive chat with Bash
What is the principle of least privilege, and how does it relate to limiting access?