ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy
A small business is implementing a new customer relationship management (CRM) system. To ensure that only authorized sales personnel can view customer contact details and only managers can approve discounts, which security principle is being primarily addressed?
- AConfidentiality
- BNon-repudiation
- CIntegrity
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: A. Confidentiality
Confidentiality ensures that information is accessible only to those authorized to have access, which directly relates to restricting access to customer contact details and discount approvals.
Why the other options are wrong
- B. Non-repudiation proves that a sender sent a message or an action was performed, which is not the focus of access control.
- C. Integrity ensures data is accurate and not improperly modified, which is not the primary concern here.
- D. Availability ensures systems and data are accessible when needed, but doesn't focus on who can access what.
Confidentiality
The security principle that ensures information is not disclosed to unauthorized individuals, entities, or processes.
- Protects sensitive data from unauthorized access.
- Often implemented through encryption, access controls, and data classification.
- One of the core tenets of the CIA triad.
Memory trick: Confidentiality keeps secrets, Integrity keeps truth, Availability keeps access.