ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy

A small non-profit organization is concerned about protecting sensitive donor information. They want to ensure that only authorized staff members can view this data. Which security principle are they primarily trying to uphold?

  1. AAvailability
  2. BIntegrity
  3. CConfidentiality
  4. DNon-repudiation
Show answer & explanation

Correct answer: C. Confidentiality

Confidentiality ensures that sensitive information is accessible only to authorized individuals, directly addressing the organization's goal of protecting donor data.

Why the other options are wrong

  • A. Availability ensures systems and data are accessible when needed, but doesn't directly address restricting access.
  • B. Integrity ensures data is accurate and not tampered with, which is a different concern than who can view it.
  • D. Non-repudiation ensures a party cannot deny an action, which is unrelated to restricting data viewing.

Confidentiality

The principle that sensitive information is protected from unauthorized access or disclosure.

  • Prevents unauthorized viewing or sharing of data.
  • Often achieved through encryption, access controls, and data classification.
  • A core component of the CIA triad.

Memory trick: Confidentiality, Integrity, and Availability: Your CIA agent protects your secrets, keeps your files true, and is always there when you call.

More Security Principles questions