PURI: http://data.europa.eu/2sa/elap/confidentiality
Category: Digital Public Service Governance
Scope: Business agnostic
Principle: Confidentiality
Statement: (Statement) Confidentiality ensures that sensitive information is protected from unauthorised access and disclosure, maintaining trust and compliance with legal and regulatory requirements.
IoP Layer: Organisational IoP, Semantic IoP, Technical IoP
Principle Source: NIS 2 Directive
About source: This directive establishes a high common level of cybersecurity across the EU. It mandates that essential and important entities implement appropriate technical and organisational measures to manage risks to the security of network and information systems, including the confidentiality of data. It also requires incident response capabilities, secure authentication, and encryption.
PA Governance: Common
Influence in DPS Implementation life-cycle: Obligation
Influence in implemented DPS attribute: Obligation
|
|
| elap:PURI | http://data.europa.eu/2sa/elap/confidentiality |
| dct:title | Confidentiality |
| dct:description | (Statement) Confidentiality ensures that sensitive information is protected from unauthorised access and disclosure, maintaining trust and compliance with legal and regulatory requirements. |
| dct:description | (Rationale) Implementing Confidentiality in solution architecture is crucial for maintaining the trust of citizens and stakeholders by safeguarding sensitive information. It helps prevent data breaches and unauthorised access, which can lead to significant legal, financial, and reputational damage. Ensuring confidentiality also supports compliance with various legal and regulatory frameworks, thereby enhancing the credibility and reliability of public sector services. |
| dct:description | (Implications) To effectively implement Confidentiality, organisations must invest in robust security measures and training programmes to ensure that all personnel understand the importance of protecting sensitive information. Business processes should be designed to minimise the risk of unauthorised access, including strict access controls and regular audits. Technically, solutions must incorporate strong encryption methods for data at rest and in transit, implement secure authentication mechanisms, and ensure continuous monitoring and incident response capabilities to detect and address potential breaches promptly. |
| elap:scope | Business agnostic |
| elap:Category | Digital Public Service Governance |
| dct:source | NIS 2 Directive |
| dct:source | https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng |
| rdfs:comment | This directive establishes a high common level of cybersecurity across the EU. It mandates that essential and important entities implement appropriate technical and organisational measures to manage risks to the security of network and information systems, including the confidentiality of data. It also requires incident response capabilities, secure authentication, and encryption. |
| dcat:theme | Organisational IoP, Semantic IoP, Technical IoP |
| elap:paGovernance | Common |
| elap:influenceInDPSLifecycle | Obligation |
| elap:influenceInDPSAttribute | Obligation |