Risk Integrity Violations and Confidentiality Breaches

Key security risks are integrity violations and confidentiality breaches.

KEY POINT

Integrity violations can occur when an attacker attempts to change sensitive data without proper authorization.

An example of an integrity violation is when an attacker obtains permission to write to sensitive data and then changes or deletes it. The owner of the data might not detect such a change until it is too late, perhaps when the change has already resulted in tangible loss. Because of the difficulty of detecting changes and the possible cascading consequences of late detection, many businesses treat integrity violations as the most serious threat to their business.

KEY POINT

Confidentiality breaches can occur when an attacker attempts to read sensitive data without proper authorization.

Confidentiality attacks can be extremely difficult to detect because the attacker can copy sensitive data without the owner's knowledge and without leaving a trace.

The risks of both integrity violations and confidentiality breaches are usually managed by enforcing access control in various ways, including the following:

■ Limiting access to network resources using network access control, such as physical separation of networks, restrictive firewalls, and VLANs.

■ Limiting access to files and objects using operating system-based access controls, such as UNIX host security and Windows domain security.

■ Limiting users' access to data by using application-level controls, such as different user profiles for different roles.

■ Using cryptography to protect data outside the application. Examples include encryption to provide confidentiality, and secure fingerprints or digital signatures to provide data authenticity and integrity. (These methods are described in the later "Secure Connectivity" section.)

Figure 10-2 illustrates potential confidentiality and integrity risks to network resources that an outside attacker might exploit. In this sample network, an attacker might do the following if adequate protection is not in place:

■ Access an internal server and copy confidential data (a confidentiality breach)

■ Deface (change) the corporate web page (an integrity breach)

■ Intercept data sent over the Internet between a branch office and the central site, and change or read it in transit (a confidentiality or integrity breach)

Figure 10-2 Integrity and Confidentiality Threats

Public Servers

Data Flow

Figure 10-2 Integrity and Confidentiality Threats

Public Servers

Data Flow

Network Breach Risk Factors
Core Servers

Continue reading here: NAC Framework and Cisco NAC Appliance

Was this article helpful?

+4 -2

Readers' Questions

  • David
    What does integrity of data refer to?
    1 year ago
  • Integrity of data refers to the accuracy and consistency of data over its entire life cycle, from creation to storage to transmission to deletion. It involves validating that data is true and accurate and that it is not modified or changed in any way. Integrity of data is highly important in order to ensure data accuracy, reliability and security.
    • Leslie
      Which protects confidentiality and integrity?
      1 year ago
    • Encryption is the most reliable way to protect the confidentiality and integrity of data. Encryption works by scrambling data so that only those with the decryption key can unscramble the data and make it readable. Encryption algorithms take data, scramble it using a secret key, and then produce what looks like random data. This random data can only be decrypted using the secret key, making it virtually impossible for anyone without the key to access the data. An added benefit of encryption is that it also protects the integrity of data, ensuring that the data has not been altered in any way.
      • mary
        Which of the following is an example of an online privacy violation?
        1 year ago
      • Unauthorized access to personal information stored online, such as names, addresses, Social Security numbers, credit card numbers, and bank account details.
        • asmara omar
          Which of the following constitutes both a breach of confidentiality?
          1 year ago
          1. Disclosing confidential information to unauthorized individuals
          2. Unnecessarily sharing confidential information with coworkers
          • Sancho
            Why do most breaches of confidentiality occur?
            1 year ago
          • Most breaches of confidentiality occur due to human error. This can include negligence such as not properly securing confidential information, or unauthorized sharing of confidential information. It can also include accidental disclosure, such as sending confidential information to the wrong person, or leaving confidential documents in a public area.
            • cora
              What is confidentiality in cyber security?
              1 year ago
            • Confidentiality in cyber security is a measure of protection for digital information, ensuring that only authorized users can access sensitive data. It can be achieved through the use of encryption, authentication, and authorization techniques to control who can see and access data stored on a system. It is an essential element of information security, as it prevents unauthorized users from gaining access to confidential information.
              • fethawit
                Which of the following is not an example of an integrity violation?
                1 year ago
              • Lying on an employment form.
                • J
                  What is integrity in cyber security?
                  1 year ago
                • Integrity in cyber security refers to the completeness and accuracy of data as it is stored, transmitted, and/or processed. It ensures that data is not modified or tampered with in any way, and that it remains unaltered and intact. Additionally, it ensures the data can be trusted and verified as authentic. Integrity is maintained through the use of access controls, data encryption, digital signatures and other measures.