Confidentiality
What is Confidentiality?
The principle of ensuring that information is accessible only to authorised individuals, entities, or processes. One of the three pillars of information security (CIA triad).
Related terms
Frameworks that govern confidentiality
What the standards actually require on confidentiality
Requirements naming confidentiality across 6 standards, quoted from the control text.
Service providers shall not disclose customer information without written consent or regulatory/legal authorization
SAM-1 · Customer Information Confidentiality (Section 48) →Hand out authentication secrets in a controlled manner that preserves confidentiality, force initial passwords to be replaced at first logon and to expire within fourteen days, inform users of resets, and store passwords as strong cryptographic hashes.
C5-IDM-08 · Confidentiality of authentication information →Security Dimensions 4 and 5 per X.805 Clauses 6.4 and 6.5 are closely related: (1) Data Confidentiality (Dim 4) protects data from unauthorized disclosure - ensures that the data content cannot be understood by unauthorized entities.
X805-Dim4-5-Data-Confidentiality-Communication-Security-Encryption-Information-Flow-Protection · ITU-T X.805 Security Dimensions 4-5 - Data Confidentiality + Communication Security + Encryption At-Rest + In-Transit + In-Use + Information Flow Protection + Steered Communication + Anti-Tap + Anti-Eavesdrop + Post-Quantum Cryptography →The identity of the reporting person shall not be disclosed, without their explicit consent, to anyone beyond the authorised staff competent to receive or follow up on reports, except where this is a necessary and proportionate obligation under Union or nation...
WB-Art.16 · Duty of confidentiality →Assess that the organization implements cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards.
3.13.8 · Transmission Confidentiality →Every person has the right to rectification, updating, and when applicable suppression or confidentiality of their personal data. Controller must act within 5 business days of the request. Free of charge.
AR-25326-ART16-RECTIFICATION · Right of Rectification, Update, Suppression and Confidentiality →Questions people ask about confidentiality
What is Confidentiality?
Why is Confidentiality important for compliance?
What concepts are related to Confidentiality?
Which compliance frameworks address Confidentiality?
Where can I learn more about Confidentiality?
See how Confidentiality applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.