The scenario described, where client files are only accessible to employees who "need to know" the information, reflects the concept of confidentiality. Confidentiality ensures that sensitive information is only accessible to those who are authorized to view it, preventing unauthorized access. Availability ensures that data is accessible when needed but doesn't focus on restricting access. Integrity ensures that data remains accurate and unaltered but doesn't pertain to access control. Non-repudiation ensures that actions cannot be denied after they are performed, but this concept is unrelated to access control.