next up previous
Next: 2.2 Policy Authority Up: 2 Security Policies Previous: 2 Security Policies

2.1 Need to Know

The military need to know policy says, in part, that individuals will not have access to information for which they have no use.

An example of this policy, when applied to a multiuser file system, might be that users have read-write access to their own files but no access to any other user's files. Such a policy may make file sharing cumbersome. An alternate policy might allow read, but not write, access to other user's files. This would go beyond need to know because a user may be able to see the contents of files he or she has no need of, even though the user is prohibited from changing such files.


next up previous
Next: 2.2 Policy Authority Up: 2 Security Policies Previous: 2 Security Policies
2002-11-26