Skip to content

Confidentiality

What is Confidentiality?

The principle of ensuring that information is accessible only to authorised individuals, entities, or processes. One of the three pillars of information security (CIA triad).

Information Security

What the standards actually require on confidentiality

Requirements naming confidentiality across 6 standards, quoted from the control text.

Service providers shall not disclose customer information without written consent or regulatory/legal authorization

SAM-1 · Customer Information Confidentiality (Section 48)
C5 (Germany)8 controls

Hand out authentication secrets in a controlled manner that preserves confidentiality, force initial passwords to be replaced at first logon and to expire within fourteen days, inform users of resets, and store passwords as strong cryptographic hashes.

C5-IDM-08 · Confidentiality of authentication information

The identity of the reporting person shall not be disclosed, without their explicit consent, to anyone beyond the authorised staff competent to receive or follow up on reports, except where this is a necessary and proportionate obligation under Union or nation...

WB-Art.16 · Duty of confidentiality
NIST SP 800-1716 controls

Assess that the organization implements cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.

3.13.8 · Transmission Confidentiality

Every person has the right to rectification, updating, and when applicable suppression or confidentiality of their personal data. Controller must act within 5 business days of the request. Free of charge.

AR-25326-ART16-RECTIFICATION · Right of Rectification, Update, Suppression and Confidentiality

Questions people ask about confidentiality

What is Confidentiality?
The principle of ensuring that information is accessible only to authorised individuals, entities, or processes. One of the three pillars of information security (CIA triad).
Why is Confidentiality important for compliance?
Confidentiality is a key concept in Information Security. Understanding confidentiality helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
What concepts are related to Confidentiality?
Key concepts related to Confidentiality include Encryption, Access Control. Understanding these interconnected concepts provides a more comprehensive view of Information Security requirements and helps organizations build holistic compliance programs.
Which compliance frameworks address Confidentiality?
Confidentiality appears in the requirement text of Samoa Telecommunications Act (2005) - Privacy & Data Protection, C5 (Germany), ITU-T X.805 - Security Architecture for End-to-End Communications, Directive (EU) 2019/1937 on the protection of persons who report breaches of Union law, NIST SP 800-171. Across these standards we have identified 41 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Confidentiality?
Explore our compliance framework pages to see how confidentiality applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Confidentiality applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.