StudyToCert

All certifications / CC / Lessons

ISC2 Certified in Cybersecurity 2026 outline · Domain 1: Security principles

Authentication, authorization and accounting (AAA), non-repudiation, privacy

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Beyond the CIA triad, the CC exam expects you to know a set of supporting ideas that describe how systems decide who can do what, and how they prove it later. The most common grouping is AAA: authentication, authorization and accounting. Many texts put identification in front of it, because a system must first be told who you claim to be.

Authentication is proving a claimed identity. You type a username (identification) and then a password, a code from an app, or a fingerprint (authentication). Authorization happens next and answers a different question: now that the system knows who you are, what are you allowed to do? File permissions, roles and access control lists are authorization mechanisms. Accounting, sometimes called auditing, records what authenticated users actually did, such as logins, file access and configuration changes, so that actions can be reviewed and traced back to a person. On the exam, watch the order: identify, authenticate, authorize, then account.

Non-repudiation means a person cannot credibly deny having performed an action, such as sending a message or approving a payment. It depends on strong authentication plus trustworthy records. Digital signatures are the classic technical example: a message signed with someone's private key could only have been signed by the holder of that key, so the signer cannot easily say it was forged. Shared accounts destroy non-repudiation because you cannot tell which of several people used the login. Detailed, tamper-resistant logs support it.

Privacy is the right of individuals to control how information about them is collected, used, shared and kept. It overlaps with confidentiality but is not the same thing. Confidentiality is a property of data that an organization protects; privacy is about people's rights and expectations, and it is often defined by law. An organization can keep data perfectly confidential and still violate privacy, for example by collecting more personal information than it needs or using it for a purpose the person never agreed to. Personally identifiable information (PII) is any information that can identify a specific person, such as a name combined with a date of birth or a national ID number.

These concepts work together. Authentication ties actions to identities, authorization limits those actions, accounting records them, non-repudiation makes the records meaningful, and privacy rules decide what personal data should be handled at all. In a lab you will see accounting in practice when you open the Windows Event Viewer security log or a Linux authentication log and find entries showing which account logged in and when.

Key terms

Authentication
Verifying that a claimed identity is genuine, for example with a password, token or biometric.
Authorization
Deciding what an authenticated identity is permitted to access or do.
Accounting
Recording the actions of authenticated users so they can be reviewed and traced; also called auditing.
Non-repudiation
Assurance that someone cannot credibly deny having performed an action, commonly provided by digital signatures and reliable logs.
Privacy
An individual's right to control the collection, use and sharing of information about them.
PII
Personally identifiable information: data that can identify a specific individual.
Real-world example

A finance team shares one login for the payment system. When an unauthorized transfer appears, the logs show only the shared account, so nobody can be held responsible. After the review, each person gets an individual account, payments require a digitally signed approval, and every action is logged, restoring accountability and non-repudiation.

Exam tip: Do not confuse authentication (who are you?) with authorization (what may you do?). Also remember that shared or generic accounts break accountability and non-repudiation, a favorite exam scenario.

Check yourself

A user logs in successfully but receives an 'access denied' message when opening a payroll folder. Which AAA element blocked them?

Authorization. Authentication succeeded, but the permissions did not allow access to that folder.

Which technology most directly provides non-repudiation for an email?

A digital signature created with the sender's private key, because only the key holder could have produced it.

How can an organization keep data confidential and still violate privacy?

By collecting or using personal data beyond what is needed or agreed, even if that data is never disclosed to outsiders.

Study CC for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CC study plan