ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementHard
A publicly traded company is preparing its annual financial report. An internal audit reveals that the company's financial data systems currently lack robust audit trails for all transactions, making it difficult to definitively prove the origin and authenticity of certain entries. This deficiency primarily impacts which of the following security principles?
- AConfidentiality
- BNon-repudiation
- CIntegrity
- DAvailability
Show answer & explanationAnswer & explanation
Correct answer: B. Non-repudiation
The issue described is the inability to 'definitively prove the origin and authenticity of certain entries.' This directly addresses the concept of non-repudiation, which ensures that a party cannot deny having performed an action or created a transaction, often enforced through audit trails and digital signatures.
Why the other options are wrong
- A. Confidentiality relates to preventing unauthorized disclosure.
- C. Integrity relates to preventing unauthorized modification and ensuring data accuracy.
- D. Availability relates to ensuring access to systems and data.
Non-repudiation
The assurance that a sender or receiver of information cannot deny having sent or received a message, respectively, and that the integrity of the message is maintained.
- Provides undeniable proof of origin and integrity.
- Often enforced through digital signatures, audit trails, and logging.
- Crucial for legal and financial transactions.
Memory trick: CIA+A for Assurance and Non-Repudiation for undeniable proof.