Confidentiality, Privacy, Encryption, and Disclosure Controls

Confidentiality, privacy, encryption, DLP, and privacy-law obligations.

This chapter separates confidentiality from privacy and explains the controls that support each objective. ISC questions here often depend on knowing whether the issue is unauthorized access, inappropriate use, or failure to comply with privacy obligations.

In This Chapter

How to Use This Chapter

  • Read this chapter when confidentiality and privacy are being treated as interchangeable.
  • Focus on what is being protected, from whom, and under which rule or obligation.
  • Revisit it whenever an ISC question asks which control best addresses data misuse or disclosure risk.

In this section

Revised on Friday, April 24, 2026