Table of Contents

4.3.4.1 Confidentiality

Return to Securability

About

Confidentiality is usually covered by the use of a Confidentiality Agreement or Non-Disclosure Agreement (NDA), which defines a set of rules or a promise limiting access or places restrictions on certain types of information. Areas that have legal agreements covering confidentiality are:

As a rule of thumb, it is best to treat all Personal Identifiable Information (PII) as confidential and to secure it (i.e., require authentication both to access the data and log access to the data).

The US National Institute of Standards and Technology (NIST) describe the kinds of data that should be treated as PII1) as:

NIST also identifies information which potentially can be used to identify people:

DIDO Specifics

Return to Top

To be added/expanded in future revisions of the DIDO RA
1)
Erika McCallister Tim Grance and Karen Scarfone, Guide to Protecting the Confidentiality of Personally Identifiable Information (PII), Special Publication 800-122, April 2010, Accessed on 13 August 2020, https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-122.pdf