- Confidentiality
- assurance of data privacy and accuracy
- keeping private or sensitive information from being disclosed to unauthorized individuals, entities, or processes
- Integrity
- assurance that stored data has not been modified without authorization
- a message that was sent is the same message that was received
- Availability
- assurance that access to data, the web site or the EC data service is timely, available , reliable and restricted to authorized users
- Authentication
- assurance the real identity of an individual , computer, computer program or EC web site
- verifies the sender of the message is who the person or organization claims to be in transmissionns
- requires evidence in the form of credentials, which can take a variety of forms, including something known(e.g:password), something possessed(e.g:a smart card), or something unique(e.g:signature)
- Authorization
- a process of determining what the authenticated entity is allowed to access and what operation it is allowed to perform
- Nonrepudiation
- assurance that online customers or trading partners cannot falsely deny their purchase of transaction including providing:-
- (a.) the sender (customer) of data with proof of delivery
- (b.) the recipient (EC company) with proof of the sender's identity
- (C.) the protect and ensure trust in EC transaction with digital signatures are used to validate the sender and time stamp of the transaction so it cannot be later claimed that the transaction was unauthorized or invalid
No comments:
Post a Comment