Preservation of confidentiality within information systems requires that the information is not disclosed to:
Correct Answer: B
Explanation/Reference:
Explanation:
Confidentiality is the assurance that information is not disclosed to unauthorized individuals, programs, or processes. Some information is more sensitive than other information and requires a higher level of confidentiality.
Confidentiality ensures that the necessary level of secrecy is enforced at each junction of data processing and prevents unauthorized disclosure. This level of confidentiality should prevail while data resides on systems and devices within the network, as it is transmitted, and once it reaches its destination.
Incorrect Answers:
A: Authorized persons are allowed to access the information.
C: Unauthorized processes should be included in the answer, not just unauthorized persons.
D: Authorized persons and processes are allowed to access the information.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, New York, 2013, p. 160