ISC2 Certified in Cybersecurity (CC)Security PrinciplesEasy
A financial institution is implementing a new online banking platform. To ensure that transactions cannot be falsely denied by either the customer or the bank after they have occurred, which security principle is most critical to implement?
- AConfidentiality
- BAvailability
- CIntegrity
- DNon-repudiation
Show answer & explanationAnswer & explanation
Correct answer: D. Non-repudiation
Non-repudiation ensures that a party cannot falsely deny having made a transaction or communication. This is crucial for financial transactions where proof of action is required.
Why the other options are wrong
- A. Confidentiality protects information from unauthorized access, but does not prevent denial of actions.
- B. Availability ensures that systems and data are accessible when needed, but doesn't address denying past actions.
- C. Integrity ensures data has not been altered or destroyed in an unauthorized manner, which is related but distinct from denying an action itself.
Non-repudiation
The assurance that someone cannot deny the validity of something, typically a statement or an action. It ensures proof of origin and delivery of data.
- Prevents individuals from denying their actions.
- Often achieved through digital signatures and audit trails.
- Critical in legal and financial transactions.
Memory trick: CIAAN is key to secure operations.