Repudiation
Repudiation is plausible deniability, or rather the inability to prove that someone did something. When you think about repudiation, you should think about threats that affect your ability to hold people accountable. Three things are required for an action to be non-repudiable: the what, the who, and the when, and this information should be immutable.
Figure 4.1: Destroying the logs/evidence
In this chapter, we will cover the threats described in the Repudiation suit in the Elevation of Privilege card deck, including an additional four cards from the T.R.I.M. extension to the game. We’ll go through some examples of repudiation threats; I’ll give you references with each example where you can get more information and I will also suggest what mitigations and controls you can put in place to protect against the threat or at least reduce the risk.
By the end of the chapter, you’ll have a better understanding and awareness of...