PURI: http://data.europa.eu/2sa/elap/non-repudiation
Category: Digital Public Service Governance
Scope: Business agnostic
Principle: Non repudiation
Statement: (Statement) Non repudiation ensures that a user or entity cannot deny having performed a specific action, such as creating, sending, receiving, or approving information, by providing undeniable proof of their involvement.
IoP Layer: Organisational IoP, Technical IoP
Principle Source: Towards Detecting and Mitigating Conflicts for Privacy and Security Requirements
About source: The article "Towards Detecting and Mitigating Conflicts for Privacy and Security Requirements" by Duaa Alkubaisy, Karl Cox, and Haralambos Mouratidis explores the identification and resolution of conflicts between privacy and security requirements in software systems.
PA Governance: Common
Influence in DPS Implementation life-cycle: Obligation
Influence in implemented DPS attribute: Obligation
|
|
| elap:PURI | http://data.europa.eu/2sa/elap/non-repudiation |
| dct:title | Non repudiation |
| dct:description | (Statement) Non repudiation ensures that a user or entity cannot deny having performed a specific action, such as creating, sending, receiving, or approving information, by providing undeniable proof of their involvement. |
| dct:description | (Rationale) Non repudiation provides significant security benefits. It ensures the integrity and authenticity of digital transactions and communications by preventing individuals or entities from denying their actions. This principle is crucial for maintaining trust and accountability in digital interactions, as it provides verifiable evidence that can be used to resolve disputes and enforce legal agreements. Non-repudiation is particularly important in contexts where sensitive data is exchanged, such as financial transactions, legal contracts, and public administration services. By implementing non-repudiation mechanisms, organisations can enhance the security and reliability of their digital services, fostering trust among users and stakeholders. |
| dct:description | (Implications) Public bodies and administrations must establish policies and procedures to ensure that all digital transactions and communications are verifiable and traceable. This involves using digital signatures, cryptographic techniques, and secure logging mechanisms to provide undeniable proof of actions. Technically, systems must be designed to support non-repudiation by incorporating robust authentication and encryption methods. Digital signatures should be used to sign documents and messages, ensuring that the origin and integrity of the data can be verified. Additionally, public administrations must ensure that these mechanisms comply with relevant legal frameworks and standards, such as the eIDAS Regulation in the EU, which provides a legal basis for electronic identification and trust services. By following these guidelines, organisations can create secure and trustworthy digital environments that prevent repudiation and enhance accountability. |
| elap:scope | Business agnostic |
| elap:Category | Digital Public Service Governance |
| dct:source | Towards Detecting and Mitigating Conflicts for Privacy and Security Requirements |
| dct:source | https://www.researchgate.net/publication/333808388_Towards_Detecting_and_Mitigating_Conflicts_for_Privacy_and_Security_Requirements |
| rdfs:comment | The article "Towards Detecting and Mitigating Conflicts for Privacy and Security Requirements" by Duaa Alkubaisy, Karl Cox, and Haralambos Mouratidis explores the identification and resolution of conflicts between privacy and security requirements in software systems. |
| dcat:theme | Organisational IoP, Technical IoP |
| elap:paGovernance | Common |
| elap:influenceInDPSLifecycle | Obligation |
| elap:influenceInDPSAttribute | Obligation |