It dodges the central issue, namely ‘Who determines “need-to-know” and how?’
Second, it mixes statements at different levels (organizational approval of a policy should logically not be part of the policy itself).
Third, there is a mechanism but it’s implied rather than explicit: ‘staff shall obey
(Ross Anderson, "#SecurityEngineering — Third Edition", PDF-Preview 2020-05-16)
[2/2]