Confidentiality
The principle that information is accessible only to those authorized to access it. Confidentiality is the first pillar of information security, ensuring sensitive data does not reach the wrong hands.
Why it matters
A confidentiality breach means unauthorized disclosure: customer data leaked, trade secrets exposed, personal information sold. The consequences range from regulatory fines (GDPR, HIPAA) to reputational destruction and competitive disadvantage. Confidentiality is not just about encryption. It encompasses access control, information classification, need-to-know principles, secure disposal, and contractual obligations like NDAs and data processing agreements.
In practice
Protecting confidentiality requires layered controls: information classification to know what is sensitive, access control to restrict who reaches it, encryption to protect it in transit and at rest, and monitoring to detect unauthorized access attempts. In vucavoid, confidentiality-related controls are linked to the information assets they protect, with classification levels driving protection requirements. Gaps between asset sensitivity and control coverage surface in your VUCA score.