Non-Repudiation
What is Non-Repudiation?
A security property that ensures a party cannot deny having performed an action, such as sending a message or authorising a transaction. Non-repudiation is typically achieved through digital signatures and audit trails.
Terms that appear alongside non-repudiation
Each of these is named in at least one of the same controls as non-repudiation. The number is how many controls name both.
- audit 9 shared controls
- integrity 8 shared controls
- nist 6 shared controls
- authentication 6 shared controls
- availability 6 shared controls
- accountability 6 shared controls
- data integrity 5 shared controls
- confidentiality 5 shared controls
Frameworks that govern non-repudiation
What the standards actually require on non-repudiation
Requirements naming non-repudiation across 6 standards, quoted from the control text.
Security Dimension 3 Non-Repudiation per X.805 Clause 6.3: Non-repudiation provides means for preventing an individual or entity from denying having performed a particular action related to data by making available proof of various network-related actions (e.g...
X805-Dim3-Non-Repudiation-Proof-Origin-Delivery-Sender-Receiver-Denial-Prevention · ITU-T X.805 Security Dimension 3 - Non-Repudiation + Proof of Origin + Proof of Delivery + Sender + Receiver Denial Prevention + Digital Signatures + Timestamping + Audit Logs + Forensic Evidence + Court-Admissible Records →Accountability and non-repudiation. Control from BSI IT-Grundschutz framework, domain: BSI IT-Grundschutz: Audit & Accountability.
BSI-32 · Accountability and non-repudiation →Accountability and non-repudiation. Implements CyFun PR.PT-1 / PR.AC-1: actions are attributable to individual users to provide accountability and non-repudiation.
BE-CF-32 · Accountability and non-repudiation →Establishes that actions taken by suppliers and integrators, and the provenance claims they make, cannot later be repudiated.
161R1-AU-10 · Non-repudiation →Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined]
NIST800-AU-10 · Non-repudiation. Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined] →GAMP 5 DATA INTEGRITY + 21 CFR PART 11 + EU ANNEX 11 alignment. ALCOA+ PRINCIPLES (FDA + EMA + MHRA Data Integrity Guidance): ATTRIBUTABLE + LEGIBLE + CONTEMPORANEOUS + ORIGINAL + ACCURATE + COMPLETE + CONSISTENT + ENDURING + AVAILABLE.
GAMP5-DataIntegrity-Part11-Annex11 · Data Integrity (ALCOA+), 21 CFR Part 11 + EU Annex 11 + Electronic Records →Questions people ask about non-repudiation
What is Non-Repudiation?
Why is Non-Repudiation important for compliance?
Which compliance frameworks address Non-Repudiation?
Where can I learn more about Non-Repudiation?
See how Non-Repudiation applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.