Cisco Certified Support Technician (CCST) CybersecuritySecurity PrinciplesHard
A financial institution is reviewing its compliance with data protection regulations like GDPR and PCI DSS. They are specifically concerned with ensuring that customer payment card data is encrypted both at rest and in transit, and that access to this data is strictly logged and audited. Which security principle is being directly addressed by these concerns?
- AConfidentiality
- BIntegrity
- CNon-repudiation
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: A. Confidentiality
Encrypting data (at rest and in transit) and strictly controlling/logging access to sensitive payment card data are measures primarily designed to prevent unauthorized disclosure of that data. This directly aligns with the principle of Confidentiality.
Why the other options are wrong
- B. Integrity ensures data is accurate and unaltered; while related, the primary concern of 'not being seen' by unauthorized parties is confidentiality.
- C. Non-repudiation ensures actions cannot be denied, which is related to logging but secondary to the core concern of preventing unauthorized viewing of data.
- D. Availability ensures data is accessible when needed, which encryption can sometimes hinder if not managed correctly, but it's not the primary focus here.
Confidentiality (CIA Triad)
The principle that sensitive information is protected from unauthorized access or disclosure. It ensures that data is only accessible to those who are authorized to view it.
- Achieved through encryption, access controls, and proper data handling.
- Prevents data breaches and unauthorized sharing.
- A fundamental pillar of information security.
Memory trick: CIA: Confidentiality is keeping secrets, Integrity is keeping truth, Availability is keeping access.