The way they do things is this. There's clearance and then there's need to know. So for instance one of my friends worked in network IT for the military. So had access to computers with "top secret" information on them. However, he wasn't allowed to access any of the information on the computers. Simply to use them for his job. Sound familiar to what the NSA is saying?
If there's other people on here that are closer to the military than I was please correct me, but it all starts to make "sense" when you think about it that way. I'm not saying it's right, in fact I think this system is likely problematic in a non military setting (and perhaps even within one as well)
Access control is one thing but:
1) How can we guarantee that the control cannot be bypassed when everything is secret? 2) How can we guarantee that someone with clearance is not selling information to criminals?
Note: this is not saying what they did was legal.
EOD launching a nuke and using PRISM data are keystrokes on a computer.