ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy
A financial institution is implementing a new customer data management system. Due to stringent regulatory requirements regarding data privacy and integrity, the organization needs to ensure that the system's security controls are designed to prevent unauthorized disclosure and modification of customer information throughout its lifecycle. Which security principle is primarily addressed by these concerns?
- ANon-repudiation
- BConfidentiality
- CAccountability
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: B. Confidentiality
Confidentiality ensures that information is not disclosed to unauthorized individuals, entities, or processes. The scenario directly addresses preventing 'unauthorized disclosure' and 'modification' of customer data, with a primary focus on disclosure through the design of security controls.
Why the other options are wrong
- A. Non-repudiation ensures that an action cannot be denied by the perpetrator, which is not the main focus.
- C. Accountability relates to tracing actions back to an entity, which is distinct from preventing unauthorized disclosure.
- D. Availability ensures timely and reliable access to data, which is not the primary concern here.
Confidentiality
The principle of preventing unauthorized disclosure of information.
- Ensures privacy and secrecy of data.
- Protects against unauthorized access and disclosure.
- Often implemented through encryption, access controls, and data classification.
Memory trick: CIA: Keep secrets, stay whole, always ready to go!