Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Cybersecurity FundamentalsEasy
A financial institution is implementing a new security policy that mandates the encryption of all customer data stored in its databases to protect against unauthorized disclosure. Which core principle of information security is this policy primarily designed to uphold?
- AIntegrity
- BConfidentiality
- CNon-repudiation
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: B. Confidentiality
Confidentiality ensures that information is accessible only to those authorized to have access. Encryption is a primary control used to achieve confidentiality by making data unreadable to unauthorized parties.
Why the other options are wrong
- A. Integrity ensures data has not been altered or tampered with, which is distinct from preventing unauthorized viewing.
- C. Non-repudiation ensures a party cannot deny having performed an action, which encryption doesn't directly provide.
- D. Availability ensures systems and data are accessible when needed, which encryption doesn't directly address.
Confidentiality
The principle that information should not be disclosed to unauthorized individuals, entities, or processes.
- Protects against unauthorized access and disclosure.
- Achieved through methods like encryption, access controls, and data masking.
- A core component of the CIA Triad.
Memory trick: CIA: C is for 'secret' information, I is for 'accurate' information, A is for 'always there' information.