
admin 2022年5月10日22:02:14评论60 views字数 3996阅读13分19秒阅读模式

Security management concepts and principles are inherent elements in a security policy and solution deployment. They define the basic parameters needed for a secure environment. They also define the goals and objectives that both policy designers and system implementers must achieve to create a secure solution.


Confidentiality, integrity, and availability (CIA) (i.e., the CIA Triad)are typically viewed as the primary goals and objectives of a security infrastructure.



Security controls are typically evaluated on how well they address these three core information security tenets. Vulnerabilities and risks are also evaluated based on the threat they pose against one or more of the CIA Triad principles



The first principle of the CIA Triad is confidentiality. Confidentiality is the concept of the measures used to ensure the protection of the secrecy of data, objects, or resources. The goal of confidentiality protection is to prevent or minimize unauthorized access to data. Confidentiality protections prevent disclosure while protecting authorized access. 


Violations of confidentiality are not limited to directed intentional attacks. Many instances of unauthorized disclosure of sensitive or confidential information are the result of human error, oversight, or ineptitude. Confidentiality violations can result from the actions of an end user or a system administrator. They can also occur because of an oversight in a security policy or a misconfigured security control. 


Numerous countermeasures can help ensure confidentiality against possible threats. These include encryption, network traffic padding, strict access control,rigorous authentication procedures, data classification, and extensive personnel training


Concepts, conditions, and aspects of confidentiality include the following: 

  • SensitivitySensitivity refers to the quality of information, which could cause harm or damage if disclosed. 

  • DiscretionDiscretion is an act of decision where an operator can influence or control disclosure in order to minimize harm or damage.

  • CriticalityThe level to which information is mission critical is its measure of criticality. The higher the level of criticality, the more likely the need to maintain the confidentiality of the information. 

  • ConcealmentConcealment is the act of hiding or preventing disclosure. Often concealment is viewed as a means of cover, obfuscation, or distraction. A related concept to concealment is security through obscurity, which is the concept of attempting to gain protection through hiding, silence,or secrecy. 

  • SecrecySecrecy is the act of keeping something a secret or preventing the disclosure of information.

  • PrivacyPrivacy refers to keeping information confidential that is personallyidentifiable or that might cause harm, embarrassment, or disgrace to someone ifrevealed. 

  • SeclusionSeclusion involves storing something in an out-of-the-way location, likely with strict access controls. 

  • IsolationIsolation is the act of keeping something separated from others. 


  • 敏感度是指信息的质量,如果披露可能会造成伤害或损害。

  • 自由裁量权是一种决定行为,经营者可以影响或控制披露,以尽量减少伤害或损害。

  • 关键性 信息对任务的关键程度是衡量其关键性的标准。关键性水平越高,就越需要保持信息的机密性。

  • 隐蔽是指隐藏或防止披露的行为。通常情况下,隐蔽被视为一种掩饰、混淆或转移注意力的手段。与隐蔽有关的一个概念是通过隐蔽获得安全,这是试图通过隐藏、沉默或保密获得保护的概念。

  • 秘密是指对某事保密或防止信息披露的行为。

  • 隐私是指对可识别个人身份的信息或一旦泄露可能对某人造成伤害、尴尬或耻辱的信息进行保密。

  • Seclusion (不会翻译是指将某样东西存放在一个不显眼的地方,可能有严格的访问控制。

  • Isolation隔离是将某物与他人分开的行为。

Organizations should evaluate the nuances of confidentiality they wish to enforce. Tools and technology that implement one form of confidentiality might not support or allow other forms. 




  • 机密性:为了限制未授权主体访问数据、客体或资源而提供的高级别保证。不能确保机密性,就会发生未授权泄露。

  • 破坏机密性的因素:

    • 故意攻击如:抓包网络流量窃取密码文件、社会工程学、端口扫描、肩窥、窃听、嗅探、特权升级等

    • 错误、疏忽或者不称职造成的未经授权的敏感或机密信息泄露。如:为正确实现的加密传输、传输数据前未对远程系统充分进行身份验证、访问恶意代码打开的后门、文件遗留在打印机上、终端显示敏感数据时不锁屏离开。

  • 维护机密性的措施:

    • 加密静止数据(整个磁盘、数据库加密)

    • 加密传输中的数据(IPSec、TLS、PPTP、SSH)

    • 访问控制(物理的和技术的)

    • 隐写术

    • 数据分类

    • 人员培训


  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
  • 本文由 发表于 2022年5月10日22:02:14
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):


匿名网友 填写信息