ISC2 CISSP (Certified Information Systems Security Professional)Security and Risk ManagementEasy

A financial institution is implementing a new customer data management system. During the planning phase, the project team identifies that certain customer data, if disclosed, could lead to severe financial penalties and reputational damage. Which of the following security principles is primarily concerned with preventing unauthorized disclosure of this sensitive information?

  1. AAvailability
  2. BNon-repudiation
  3. CIntegrity
  4. DConfidentiality
Show answer & explanation

Correct answer: D. Confidentiality

Confidentiality is the principle that ensures sensitive information is protected from unauthorized disclosure. In this scenario, preventing financial penalties and reputational damage from data disclosure directly aligns with confidentiality.

Why the other options are wrong

  • A. Availability focuses on ensuring authorized users can access information and systems when needed, not preventing disclosure.
  • B. Non-repudiation ensures that a party cannot deny having performed an action, which is distinct from preventing unauthorized disclosure.
  • C. Integrity focuses on preventing unauthorized modification or destruction of data, not disclosure.

Confidentiality

The security principle that protects information from unauthorized disclosure. It ensures that only authorized individuals, entities, or processes can access sensitive data.

  • Prevents unauthorized disclosure of information.
  • Related to privacy and secrecy.
  • Often implemented using encryption, access controls, and data classification.

Memory trick: Confidentiality, Integrity, Availability: three pillars of InfoSec.

More Security and Risk Management questions