CRISC Certified in Risk and Information Systems ControlRisk Response and ReportingMedium

A retail company has identified that its point-of-sale (POS) systems are vulnerable to malware attacks, potentially leading to credit card data theft. To address this, the company implements end-to-end encryption for all credit card transactions, tokenization of cardholder data, and strict network segmentation for POS devices. These controls are primarily designed to achieve which of the following control objectives?

  1. AAvailability
  2. BNon-repudiation
  3. CConfidentiality
  4. DIntegrity
Show answer & explanation

Correct answer: C. Confidentiality

Encryption, tokenization, and network segmentation are all measures aimed at preventing unauthorized access to sensitive credit card data, thereby protecting its confidentiality.

Why the other options are wrong

  • A. Availability ensures systems and data are accessible when needed, which is not the primary goal of these specific controls.
  • B. Non-repudiation ensures that transactions or actions cannot be denied, which is not the primary objective of preventing data theft.
  • D. Integrity ensures data is accurate and unaltered, while these controls protect against unauthorized *disclosure*, not necessarily alteration.

Control Objective: Confidentiality

Protecting sensitive information from unauthorized access and disclosure to unauthorized individuals or systems.

  • Prevents data breaches and leaks.
  • Achieved through encryption, access controls, data masking.
  • Critical for privacy and competitive advantage.

Memory trick: CIA+N: Confidentiality, Integrity, Availability, Non-repudiation.

More Risk Response and Reporting questions