Glossary

Confidentiality

Principle ensuring that information is not disclosed to unauthorized parties, one of the three elements of the CIA Triad.

A

B

C

Confidentiality is one of the three pillars of the CIA Triad (alongside Integrity and Availability) and ensures that information is accessible only to those who are authorised to view it. It is maintained through a combination of access controls, encryption, data classification and security awareness training.

Breaches of confidentiality can result in regulatory penalties under GDPR, loss of competitive advantage and reputational damage. ISO 27001 addresses confidentiality through multiple Annex A controls covering areas such as access management, cryptography, physical security and supplier relationships. Organisations must continuously assess and strengthen their confidentiality measures as threats evolve.

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What is confidentiality in information security?
Confidentiality is the principle that information is only accessible to authorised people and not disclosed to unauthorised parties.
What are the three elements of the CIA triad?
Confidentiality, Integrity and Availability, the three core principles of information security.
How is confidentiality protected?
Through controls such as access control, encryption, and classification of information.