Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesMedium
A hospital's IT department is reviewing its data backup strategy after a recent ransomware attack that encrypted patient records. They need to ensure that critical patient data can be restored quickly and efficiently to minimize disruption to patient care. Which security principle is primarily addressed by a robust and tested data backup and recovery plan?
- ANon-repudiation
- BConfidentiality
- CAvailability
- DIntegrity
Show answer & explanationAnswer & explanation
Correct answer: C. Availability
Availability ensures that systems and data are accessible and usable when needed. A robust data backup and recovery plan is crucial for restoring service and data after an incident, directly supporting availability.
Why the other options are wrong
- A. Non-repudiation deals with proving actions, not with the ability to access data after an incident.
- B. Confidentiality focuses on preventing unauthorized disclosure, not on restoring access after an attack.
- D. Integrity ensures data accuracy, but the primary concern of recovery is access to data, not just its accuracy.
Availability
The security principle that ensures authorized users have timely and uninterrupted access to information and resources when needed.
- Ensures uptime and access.
- Achieved through redundancy, backups, disaster recovery, and fault tolerance.
- Part of the CIA triad.
Memory trick: Availability means 'always on' for everyone authorized.