Confidentiality
Confidentiality is the degree to which a system ensures that data is disclosed and made available only to authorized parties. It’s one of the classic security goals, alongside integrity and availability, and it’s compromised whenever information reaches someone who was never entitled to see it – whether through a deliberate attack, a misconfiguration, or careless handling.
ISO/IEC 25010 classifies confidentiality as a quality attribute, specifically a sub-characteristic of security. Achieving it in practice relies on authentication to establish who is asking, and authorization to decide what they’re allowed to see, backed by controls such as encryption of data at rest and in transit.
References
- ISO/IEC (2023). ISO/IEC 25010:2023 — Systems and software Quality Requirements and Evaluation (SQuaRE) — Quality model.