Almost every security decision can be traced back to a small set of goals. The oldest and most tested is the CIA triad: confidentiality, integrity and availability. SSCP adds three more ideas you must separate cleanly: authenticity, non-repudiation and privacy. Exam questions often describe a control or an attack and ask which goal it serves or threatens, so the definitions need to be crisp.
Confidentiality means information is disclosed only to authorized people, processes and systems. Controls include encryption, access control lists and data classification. Eavesdropping, shoulder surfing and a misconfigured public storage bucket all threaten it. Integrity means information and systems are protected from unauthorized or accidental change, and that changes can be detected. Hashes, digital signatures, input validation and change control support integrity. Availability means authorized users can reach systems and data when they need them. Redundancy, backups, patching and capacity planning support it, while denial-of-service attacks, ransomware and power failures threaten it.
Authenticity means you can confirm that data, a message or a user is genuine: that it really came from the claimed source. A message authentication code or a digital signature proves authenticity of a message; a successful login proves authenticity of a user. Non-repudiation goes a step further. It means the sender cannot credibly deny having performed an action, such as signing a contract or approving a payment. Non-repudiation needs something only that person could have produced, which is why it relies on asymmetric digital signatures with a private key the signer alone controls, plus trustworthy logging and timestamps.
A classic exam distinction: a shared secret key, as used in a hash-based message authentication code (HMAC), proves a message came from someone holding the key and was not altered, so it gives integrity and authenticity. It does not give non-repudiation, because both parties hold the same key and either could have produced the code. Only a signature made with a private key that one party alone holds can support non-repudiation.
Privacy is related to confidentiality but not the same. Confidentiality is about keeping any sensitive information from unauthorized eyes. Privacy is about individuals' rights over their own personal information: what is collected, why, how long it is kept, who it is shared with, and whether the person consented. You can protect data perfectly well (confidentiality) and still violate privacy by collecting more than you need or using it for an undisclosed purpose.
When you read a scenario, ask what went wrong or what is being protected. Data seen by the wrong person is confidentiality. Data changed is integrity. Service down is availability. Uncertainty about who sent something is authenticity. Someone denying an action is non-repudiation. Misuse of personal data is privacy.
Key terms
- Confidentiality
- Preventing disclosure of information to unauthorized people, processes or systems.
- Integrity
- Protecting data and systems from unauthorized or accidental modification and making changes detectable.
- Availability
- Ensuring authorized users have timely, reliable access to systems and data.
- Non-repudiation
- Assurance that a party cannot credibly deny having performed an action, typically achieved with a private-key digital signature and reliable logs.
- Privacy
- An individual's right to control how their personal information is collected, used, shared and retained.
A finance clerk approves a large wire transfer, then later claims they never did. Because the approval system requires each approver to sign with a private key stored on their own smart card, and the action is recorded in a protected audit log, the company can show the approval came from the clerk's credential. That is non-repudiation at work.
Check yourself
A ransomware attack encrypts a file server so staff cannot open files. Which CIA goal is most directly affected?
Availability, because authorized users can no longer access the data when they need it.
Why does a shared-key message authentication code not provide non-repudiation?
Both parties hold the same key, so either could have created the code; you cannot prove which one did.
How does privacy differ from confidentiality?
Confidentiality protects any sensitive data from unauthorized disclosure; privacy concerns individuals' rights over how their personal data is collected, used and shared.