Authenticity
The principle that information, communications, and transactions are genuine and originate from the claimed source. Authenticity proves that something is what it claims to be, not forged, spoofed, or impersonated.
Why it matters
Confidentiality, integrity, and availability protect information. Authenticity protects trust. A phishing email that impersonates your CEO, a forged digital certificate, a manipulated invoice from a spoofed vendor address: these attacks succeed because authenticity was not verified. As AI-generated content makes forgery easier, authenticity verification becomes more critical. Without it, your organization cannot distinguish legitimate communications from social engineering.
In practice
Authenticity controls include multi-factor authentication, digital signatures, certificate management, email authentication (SPF, DKIM, DMARC), and identity verification procedures for sensitive transactions. In vucavoid, authenticity is enforced through user attribution on every action, timestamped evidence with clear provenance, and the Compliance ID that provides external-facing proof that your compliance posture is genuine and verifiable, not just claimed.