Non-Repudiation
Definition
The property that a party cannot deny having performed an action. Provided by digital signatures, timestamped audit logs, and certified delivery receipts. Extends integrity by tying changes to an authenticated identity.
- Provided by
- Digital signatures, timestamped audit logs, certified delivery receipts
- Relation to integrity
- Ties a change to an authenticated identity
- Triad status
- Not one of the original CIA triad elements, but a common extension
- Typical use
- Proving who sent, approved, or altered a record
Common questions
How is non-repudiation different from plain data integrity?+
Integrity only shows that data has not been altered, while non-repudiation goes further by cryptographically binding an action to a specific identity, so that party cannot later plausibly deny having performed it.
Why does non-repudiation matter in a forensic investigation?+
It lets an investigator show, with evidentiary weight, that a particular user account or system actually generated a log entry, signed a document, or sent a message, rather than the record having been inserted or spoofed by someone else.
Related terms
- Availability
- The property that systems and data are accessible to authorised users when needed. Protected by redundancy, backup, failover, and incident response capabilities....
- Confidentiality
- The property that information is not disclosed to unauthorised individuals, processes, or devices. Protected by access controls, encryption, and need-to-know policies. Breached...
- Integrity
- The property that information is accurate, complete, and has not been modified without authorisation. Protected by cryptographic hashing, digital signatures, and change...
- Threat
- A potential cause of an unwanted incident that could harm an asset. Threats may be natural (flood, fire), environmental (power failure), human...
- Vulnerability
- A weakness in an asset or in a control protecting that asset, which a threat could exploit to cause harm. Examples: an...