# Need to Know **Entity class:** Security, Compliance, And Authorization Layer concept **Need to Know** is a concept in the security, compliance, and authorization of the counterterrorism predictive-graph ontology. Within a predictive graph, Need to Know helps separate recorded evidence from the hidden state inferred from that evidence. ## Counterterrorism predictive-graph role Its controls are part of the computational trust fabric, not peripheral paperwork: permissions, provenance, purpose, and auditability must remain machine-enforceable across systems. The analytic state should distinguish ground truth, observed evidence, inferred state, and predicted state. ## Relationships - **domain router:** [[wiki/Assurance Infrastructure|Assurance Infrastructure]]. - **ontology neighbors:** [[wiki/Role-Based Access Control|Role-Based Access Control]] and [[wiki/Least Privilege|Least Privilege]]. - **synthesis:** [[wiki/Counterterrorism Predictive Graph|Counterterrorism Predictive Graph]] and [[wiki/Predictive Intelligence Loop|Predictive Intelligence Loop]]. ## Sources - [NIST SP 800-53 Rev. 5, Release 5.2.0, August 27, 2025](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) - [ODNI — ICD 503, Intelligence Community Information Technology Systems Security Risk Management, September 15, 2008](https://www.dni.gov/files/documents/ICD/ICD_503.pdf) **As of:** 2026-09-23