Which list contains the information security goals that should be achieved by an e-commerce system for users and asset holders?

Prepare for the Coach CFE Exam. Study using flashcards and multiple-choice questions, each with hints and explanations. Get ready for your assessment!

Multiple Choice

Which list contains the information security goals that should be achieved by an e-commerce system for users and asset holders?

Explanation:
The essential idea here is to protect information and services across confidentiality, integrity, availability, authentication, and non-repudiation. For an e-commerce system, these goals translate into protecting customer data and payments (confidentiality), ensuring orders and transaction records are accurate and tamper-proof (integrity), keeping the site and services accessible when customers need them (availability), verifying who is using the system to prevent unauthorized actions (authentication), and providing verifiable evidence of who performed actions like purchases or changes (non-repudiation). This combination directly addresses both users and asset holders by guarding privacy, correctness, reliability, identity, and accountability. Other options include nonstandard terms or omit one of these critical elements, so they don’t fully capture the necessary security goals.

The essential idea here is to protect information and services across confidentiality, integrity, availability, authentication, and non-repudiation. For an e-commerce system, these goals translate into protecting customer data and payments (confidentiality), ensuring orders and transaction records are accurate and tamper-proof (integrity), keeping the site and services accessible when customers need them (availability), verifying who is using the system to prevent unauthorized actions (authentication), and providing verifiable evidence of who performed actions like purchases or changes (non-repudiation). This combination directly addresses both users and asset holders by guarding privacy, correctness, reliability, identity, and accountability. Other options include nonstandard terms or omit one of these critical elements, so they don’t fully capture the necessary security goals.

Subscribe

Get the latest from Passetra

You can unsubscribe at any time. Read our privacy policy