Confidentiality Concepts
When someone submits a message so that only the intended individual can read it, it is considered confidential. Confidentiality controls protect data from being disclosed to unauthorized parties.
This is done via several controls, including the following:
- Encryption
- Passwords
- Access control lists
- Steganography
- Physical locks
Private records, financial reports, and tax identification numbers are generically called objects, and they are protected by a set of rules defined as the access matrix monitor. So, does the user, viewer, or reader, also known as the subject, have the privilege to access the data? How objects respond to subjects is referred to as the access control model, which is shown in Figure 1.3. There are several variations of access control models discussed in Chapter 7, Secure Design Principles and Controls. For example, some objects are defined as read-only. In this scenario, viewing these objects is allowed by...