08 Confidentiality
The Confidentiality Trust Services category focuses on protecting information that an organization has designated as confidential.
Examples may include:
Customer Data
Source Code
Trade Secrets
Contracts
Internal Financial Information
Business Strategy
Security Architecture
Proprietary DataThe key question is:
Can the organization demonstrate that confidential information is identified, protected, accessed only by authorized users, securely shared, retained appropriately, and securely disposed of when no longer required?
A strong confidentiality lifecycle looks like:
Identify Data ↓Classify ↓Restrict Access ↓Encrypt ↓Monitor Use ↓Control Sharing ↓Retain ↓Dispose ↓EvidenceFor GRC professionals, Confidentiality connects data governance, IAM, encryption, third-party risk, retention, and security monitoring into one assurance model.
Learning Objectives
Section titled “Learning Objectives”By the end of this lesson, you will be able to:
-
Explain the SOC 2 Confidentiality category.
-
Distinguish Confidentiality from Privacy.
-
Identify confidential information.
-
Build data-classification models.
-
Maintain confidential-data inventories.
-
Map classification to protection requirements.
-
Govern access to confidential information.
-
Apply least privilege and need-to-know principles.
-
Understand encryption requirements.
-
Govern cryptographic keys.
-
Protect confidential information in transit.
-
Govern data sharing.
-
Assess third-party confidentiality controls.
-
Define retention requirements.
-
Establish secure-disposal controls.
-
Monitor confidential-data activity.
-
Define appropriate confidentiality evidence.
-
Test design and operating effectiveness.
-
Build practical Confidentiality artifacts.
1. What Is Confidentiality?
Section titled “1. What Is Confidentiality?”Confidentiality means protecting information from unauthorized disclosure.
Conceptually:
Confidential Information ↓Authorized Users Only ↓Approved Purpose ↓Controlled AccessA confidentiality failure occurs when information is disclosed to someone who should not have access.
2. Confidentiality vs Security
Section titled “2. Confidentiality vs Security”Security is broader.
Security→ Protect systems and information against threats
Confidentiality→ Prevent unauthorized disclosure of designated informationA system may be secure in many respects while still having poor confidentiality controls.
3. Confidentiality vs Privacy
Section titled “3. Confidentiality vs Privacy”Confidentiality and Privacy overlap, but they are not the same.
Confidentiality→ Protect information designated confidential
Privacy→ Govern personal information and its lifecycleExample:
Source Code→ Confidential→ Not necessarily personal informationEmployee PII may be:
Confidential+Privacy-Regulated4. What Information Is Confidential?
Section titled “4. What Information Is Confidential?”Examples include:
Customer Contracts
Source Code
Pricing Models
Security Designs
Business Plans
API Secrets
Product Roadmaps
Internal Financial ReportsThe organization should formally define which information requires confidentiality protection.
5. Information Classification
Section titled “5. Information Classification”A common model is:
Public
Internal
Confidential
RestrictedEach classification should have defined handling requirements.
6. Example Classification Model
Section titled “6. Example Classification Model”| Classification | Example | Protection Level |
|---|---|---|
| Public | Marketing Content | Low |
| Internal | Internal Procedures | Moderate |
| Confidential | Customer Contracts | High |
| Restricted | Critical Secrets | Highest |
7. Why Classification Matters
Section titled “7. Why Classification Matters”Without classification:
All Data ↓Same ControlsThis is inefficient.
With classification:
Data ↓Classification ↓Required ControlsProtection becomes risk based.
8. Classification Policy
Section titled “8. Classification Policy”A control may state:
Information is classified according to sensitivity, business impact, contractual obligations, and applicable requirements.
9. Classification Criteria
Section titled “9. Classification Criteria”Possible factors:
Business Sensitivity
Customer Commitment
Contract Requirement
Legal Requirement
Competitive Value
Security Impact10. Data Ownership
Section titled “10. Data Ownership”Every important information asset should have an accountable owner.
Example:
Customer Contracts→ Legal
Source Code→ Engineering
Security Architecture→ SecurityThe owner may determine:
Classification
Access
Retention
Sharing11. Build Data Classification Register
Section titled “11. Build Data Classification Register”Create:
01 Data Classification RegisterUse:
| Data Asset | Owner | Classification | Location | Requirement |
|---|
12. Confidential Data Inventory
Section titled “12. Confidential Data Inventory”Organizations should know where confidential information resides.
Potential locations include:
Databases
Object Storage
SaaS
File Shares
Source Repositories
Endpoints
Backups
Email13. Why Inventory Matters
Section titled “13. Why Inventory Matters”If you cannot answer:
Where is our confidential information?
you cannot reliably control:
Access
Encryption
Retention
Sharing
Deletion14. Build Confidential Data Inventory
Section titled “14. Build Confidential Data Inventory”Create:
02 Confidential Data InventoryUse:
| Data | System | Owner | Classification | Region | Encryption |
|---|
15. Data Discovery
Section titled “15. Data Discovery”Organizations may use:
Manual Inventory
Data Catalog
DLP
Cloud Discovery
Classification Toolsto identify sensitive data.
16. Data Labeling
Section titled “16. Data Labeling”Some organizations apply labels such as:
CONFIDENTIAL
RESTRICTED
INTERNALto documents or data sets.
Labels can support:
Access Control
DLP
Sharing Restrictions
Retention17. Access Restriction
Section titled “17. Access Restriction”Confidential information should be accessible only to authorized users.
A common principle is:
Need to Know+Least Privilege18. Need to Know
Section titled “18. Need to Know”A user may work for the company but still not need access to every confidential dataset.
Example:
Marketing Employee≠Access to M&A Documents19. Role-Based Access
Section titled “19. Role-Based Access”Use roles where practical.
Example:
Legal Team ↓Contract Repository Accessrather than individual unmanaged permissions.
20. Access Approval
Section titled “20. Access Approval”Control example:
Access to Confidential and Restricted information requires approval from the applicable data owner or authorized delegate.
21. Access Evidence
Section titled “21. Access Evidence”Examples:
Access Request
Approval
Assigned Role
Data Owner
Provisioning Record22. Access Reviews
Section titled “22. Access Reviews”Periodic reviews should identify:
Excessive Access
Former Employees
Role Changes
Dormant Accounts
Unauthorized External Users23. Access Review Control
Section titled “23. Access Review Control”Access to Confidential and Restricted information repositories is reviewed periodically by authorized data owners.
24. Privileged Access
Section titled “24. Privileged Access”Administrators may have broad technical access to confidential information.
Controls may include:
MFA
PAM
Logging
Just-in-Time Access
Periodic Review25. Privileged Access Risk
Section titled “25. Privileged Access Risk”Example:
Database Administrator ↓Can Access Customer DataEven if the business application restricts normal users, privileged infrastructure access must also be considered.
26. Service Accounts
Section titled “26. Service Accounts”Applications may access confidential information.
Therefore review:
Service Account
API Identity
Permissions
Credential Protection
Ownership27. Data Access Logging
Section titled “27. Data Access Logging”Sensitive repositories should log important access where appropriate.
Examples:
File Downloads
Database Queries
Administrative Access
Sharing Changes28. Encryption at Rest
Section titled “28. Encryption at Rest”Confidential information may require encryption while stored.
Examples:
Database Encryption
Disk Encryption
Object Storage Encryption
Backup Encryption29. Encryption Control
Section titled “29. Encryption Control”Confidential and Restricted information stored in approved systems is encrypted at rest using approved cryptographic mechanisms.
30. Encryption Evidence
Section titled “30. Encryption Evidence”Examples:
Storage Configuration
Database Configuration
Key Settings
Encryption Coverage Report31. Encryption in Transit
Section titled “31. Encryption in Transit”Confidential information should be protected when transmitted.
Examples:
HTTPS
TLS
VPN
Secure File Transfer32. Weak Transport
Section titled “32. Weak Transport”Avoid:
HTTP
Plain FTP
Unencrypted Administrative Protocolfor confidential information.
33. Transport Encryption Control
Section titled “33. Transport Encryption Control”Confidential information transmitted across untrusted networks is protected using approved encrypted communication protocols.
34. Key Management
Section titled “34. Key Management”Encryption is only as strong as its key management.
Controls should address:
Key Creation
Storage
Access
Rotation
Revocation
Deletion35. Who Can Access Keys?
Section titled “35. Who Can Access Keys?”Ask:
Who administers keys?
Who can use keys?
Who can decrypt data?
Who reviews access?36. Key Segregation
Section titled “36. Key Segregation”A strong design may separate:
Data Administrationfrom:
Key Administrationwhere appropriate.
37. Customer-Managed Keys
Section titled “37. Customer-Managed Keys”Some organizations may require:
Customer-Managed Encryption Keysfor high-sensitivity information.
This can provide stronger control but adds operational responsibility.
38. Key Rotation
Section titled “38. Key Rotation”Example control:
Cryptographic keys protecting Confidential and Restricted information are rotated according to defined security requirements.
39. Key Access Evidence
Section titled “39. Key Access Evidence”Examples:
Key IAM Policy
Administrator List
Usage Logs
Access Review40. Secrets Management
Section titled “40. Secrets Management”Secrets may include:
Passwords
API Keys
Tokens
Private Keys
Database CredentialsThese should be treated as highly sensitive.
41. Secrets Storage
Section titled “41. Secrets Storage”Avoid:
Source Code
Spreadsheets
Email
Plaintext FilesUse approved secret-management mechanisms.
42. Source Code Confidentiality
Section titled “42. Source Code Confidentiality”Source code can be highly valuable confidential information.
Controls may include:
Repository Access
Branch Protection
MFA
Logging
External Collaborator Review43. Repository Access Review
Section titled “43. Repository Access Review”Review:
Employees
Contractors
External Developers
Service Accounts44. Data Sharing
Section titled “44. Data Sharing”Confidential information often needs to be shared.
The process should control:
Recipient
Purpose
Method
Approval
Duration45. Internal Sharing
Section titled “45. Internal Sharing”Example:
Confidential Contract ↓Legal + FinanceAvoid unnecessary organization-wide access.
46. External Sharing
Section titled “46. External Sharing”Before sending confidential information outside the organization, consider:
Recipient Authorization
Contractual Protection
Secure Transfer
Data Minimization47. External Sharing Control
Section titled “47. External Sharing Control”Confidential information may be shared externally only with authorized recipients using approved secure-transfer mechanisms and required contractual protections.
48. Sharing Register
Section titled “48. Sharing Register”Create:
03 Confidential Data Sharing RegisterUse:
| Data | Recipient | Purpose | Method | Approval | Expiry |
|---|
49. Public Links
Section titled “49. Public Links”SaaS platforms may allow:
Anyone With Linksharing.
This creates confidentiality risk.
Monitor:
Public Links
Anonymous Sharing
Guest Accounts50. External Collaborators
Section titled “50. External Collaborators”Review:
Business Need
Sponsor
Access Level
Expiry51. Data Loss Prevention
Section titled “51. Data Loss Prevention”DLP may help detect:
Sensitive Email Attachment
Confidential Upload
Unauthorized USB Copy
External File SharingDLP is one potential detective control.
52. DLP Does Not Replace Governance
Section titled “52. DLP Does Not Replace Governance”A DLP product alone does not define:
What is confidential?
Who may share it?
With whom?
Under what conditions?Policies and ownership remain necessary.
53. Third-Party Confidentiality
Section titled “53. Third-Party Confidentiality”Vendors may process confidential information.
The organization should understand:
What Data?
Why?
Where?
Who Accesses It?
What Controls?54. Vendor Risk Assessment
Section titled “54. Vendor Risk Assessment”For providers handling confidential data assess:
SOC 2
ISO 27001
Encryption
Access Controls
Incident Response
Subprocessors
Deletion55. Contractual Confidentiality
Section titled “55. Contractual Confidentiality”Contracts may include:
Confidentiality Clause
Security Requirements
Use Restrictions
Incident Notification
Return / Deletion56. Minimum Necessary Data
Section titled “56. Minimum Necessary Data”Do not provide a vendor with:
Entire Customer Databasewhen it only requires:
Customer ID+EmailData minimization reduces confidentiality exposure.
57. Subprocessors
Section titled “57. Subprocessors”A provider may share information with:
Cloud Provider
Support Provider
Analytics Provider
SubprocessorThese dependencies should be known.
58. Third-Party Sharing Map
Section titled “58. Third-Party Sharing Map”Conceptually:
Organization ↓SaaS Provider ↓Cloud Provider ↓Support ProviderConfidentiality obligations should follow the data.
59. Cloud Confidentiality
Section titled “59. Cloud Confidentiality”Cloud controls may include:
Approved Regions
Encryption
IAM
Private Networking
Logging
Provider Assurance60. SaaS Confidentiality
Section titled “60. SaaS Confidentiality”For SaaS platforms review:
Admin Access
External Sharing
Encryption
Data Export
Logs
Retention
Deletion61. Endpoint Confidentiality
Section titled “61. Endpoint Confidentiality”Confidential data may reach employee endpoints.
Controls may include:
Disk Encryption
Screen Lock
EDR
USB Restrictions
Remote Wipe62. Mobile Devices
Section titled “62. Mobile Devices”If confidential data is accessible from mobile devices, consider:
MDM
Encryption
Device Lock
Remote Wipe
Application Controls63. Printing
Section titled “63. Printing”Confidentiality applies to physical copies too.
Controls may include:
Secure Printing
Restricted Areas
Shredding
Clean Desk64. Email
Section titled “64. Email”Email is a common confidentiality channel.
Risks include:
Wrong Recipient
Forwarding
Personal Email
Unencrypted Attachment65. Secure Messaging
Section titled “65. Secure Messaging”For highly sensitive information, organizations may use:
Secure Portal
Encrypted Messaging
Approved File Transferinstead of normal email.
66. Confidentiality and Retention
Section titled “66. Confidentiality and Retention”Keeping confidential information longer than required increases exposure.
Therefore define:
Retention Period
Retention Reason
Deletion Trigger
Owner67. Retention Requirements
Section titled “67. Retention Requirements”Requirements may come from:
Business Need
Contract
Law
Policy
Litigation Hold68. Retention Schedule
Section titled “68. Retention Schedule”Example:
| Data | Retention |
|---|---|
| Customer Contract | Contract + 7 Years |
| Security Logs | 1 Year |
| Source Code | Business Need |
| Temporary Export | 30 Days |
69. Retention Control
Section titled “69. Retention Control”Confidential information is retained according to approved business, legal, contractual, and security requirements.
70. Retention Evidence
Section titled “70. Retention Evidence”Examples:
Retention Policy
System Configuration
Deletion Job
Retention Report71. Legal Holds
Section titled “71. Legal Holds”Normal deletion may be suspended because of:
Litigation
Investigation
Regulatory HoldLegal-hold requirements should be governed.
72. Secure Disposal
Section titled “72. Secure Disposal”At the end of retention:
Confidential Data ↓Secure Disposal73. Digital Disposal
Section titled “73. Digital Disposal”Possible methods include:
Logical Deletion
Cryptographic Erasure
Secure Media Erasurebased on technology and requirements.
74. Physical Disposal
Section titled “74. Physical Disposal”Examples:
Shredding
Media Destruction
Certified Disposal75. Disposal Control
Section titled “75. Disposal Control”Confidential information and associated media are securely disposed of when retention requirements expire and no authorized hold applies.
76. Disposal Evidence
Section titled “76. Disposal Evidence”Examples:
Deletion Logs
Destruction Certificates
Ticket
System Record77. Cloud Data Deletion
Section titled “77. Cloud Data Deletion”Cloud environments complicate deletion.
Copies may exist in:
Primary Storage
Replication
Backups
Logs
ArchivesDeletion procedures should account for the service architecture.
78. SaaS Offboarding
Section titled “78. SaaS Offboarding”When terminating a SaaS provider:
Export Required Data
Revoke Access
Remove Integrations
Request Deletion
Confirm Deletion79. Provider Deletion Confirmation
Section titled “79. Provider Deletion Confirmation”Evidence may include:
Deletion Certificate
Provider Confirmation
Contract Closure80. Confidentiality Incident
Section titled “80. Confidentiality Incident”Examples include:
Email Sent to Wrong Recipient
Public Storage Exposure
Lost Laptop
Unauthorized Download
Vendor Disclosure81. Incident Response
Section titled “81. Incident Response”Confidentiality incidents should be handled through the security incident process.
Detect ↓Contain ↓Identify Data ↓Assess Exposure ↓Notify ↓Remediate82. Exposure Assessment
Section titled “82. Exposure Assessment”Ask:
What data?
Which classification?
How many records?
Who received it?
Was encryption present?
Was data accessed?83. Confidentiality Monitoring
Section titled “83. Confidentiality Monitoring”Useful signals include:
Bulk Downloads
External Sharing
Public Links
Unusual Database Access
DLP Alerts
Privilege Changes84. Monitoring Control
Section titled “84. Monitoring Control”Security monitoring mechanisms identify and investigate material events involving unauthorized access to or disclosure of confidential information.
85. Confidentiality Evidence
Section titled “85. Confidentiality Evidence”Examples:
Data Inventory
Access Reports
Encryption Reports
DLP Alerts
Sharing Logs
Retention Evidence
Deletion Evidence86. Build Confidentiality Control Matrix
Section titled “86. Build Confidentiality Control Matrix”Create:
04 Confidentiality Control MatrixUse:
| Control ID | Risk | Control | Owner | Evidence |
|---|
87. Example Confidentiality Controls
Section titled “87. Example Confidentiality Controls”CONF-001Information Classification
CONF-002Confidential Data Inventory
CONF-003Confidential Data Access
CONF-004Access Review
CONF-005Encryption at Rest
CONF-006Encryption in Transit
CONF-007Key Management
CONF-008External Sharing
CONF-009Third-Party Confidentiality
CONF-010Retention
CONF-011Secure Disposal
CONF-012Confidential Data Monitoring88. CONF-001 — Information Classification
Section titled “88. CONF-001 — Information Classification”Information is classified according to sensitivity, business impact, contractual obligations, and applicable requirements.
89. CONF-002 — Data Inventory
Section titled “89. CONF-002 — Data Inventory”Confidential and Restricted information repositories are identified and maintained in an approved data inventory.
90. CONF-003 — Confidential Access
Section titled “90. CONF-003 — Confidential Access”Access to Confidential and Restricted information is restricted according to need-to-know and least-privilege principles.
91. CONF-004 — Access Review
Section titled “91. CONF-004 — Access Review”Access to critical confidential-information repositories is periodically reviewed by authorized data owners.
92. CONF-005 — Encryption at Rest
Section titled “92. CONF-005 — Encryption at Rest”Confidential and Restricted information stored in approved systems is encrypted at rest using approved cryptographic mechanisms.
93. CONF-006 — Encryption in Transit
Section titled “93. CONF-006 — Encryption in Transit”Confidential information transmitted across untrusted networks uses approved encryption protocols.
94. CONF-007 — Key Management
Section titled “94. CONF-007 — Key Management”Cryptographic keys protecting Confidential and Restricted information are securely generated, stored, accessed, rotated, and retired according to approved standards.
95. CONF-008 — External Sharing
Section titled “95. CONF-008 — External Sharing”External disclosure of Confidential information requires authorized business need, approved sharing mechanisms, and appropriate protection.
96. CONF-009 — Third-Party Confidentiality
Section titled “96. CONF-009 — Third-Party Confidentiality”Third parties receiving Confidential information are subject to risk-based security review and contractual confidentiality obligations.
97. CONF-010 — Retention
Section titled “97. CONF-010 — Retention”Confidential information is retained only for approved business, legal, regulatory, or contractual periods.
98. CONF-011 — Secure Disposal
Section titled “98. CONF-011 — Secure Disposal”Confidential information is securely deleted or destroyed when retention requirements expire.
99. CONF-012 — Monitoring
Section titled “99. CONF-012 — Monitoring”Material access, sharing, and security events involving Confidential information are logged and monitored according to risk.
100. Encryption Evidence Register
Section titled “100. Encryption Evidence Register”Create:
05 Encryption Evidence RegisterUse:
| System | Data | At Rest | In Transit | Key Model | Status |
|---|
101. Confidential Sharing Register
Section titled “101. Confidential Sharing Register”Create:
06 Confidential Data Sharing RegisterUse:
| Data | Recipient | Internal/External | Approval | Method | Status |
|---|
102. Retention & Disposal Register
Section titled “102. Retention & Disposal Register”Create:
07 Retention & Disposal RegisterUse:
| Data | Retention | Trigger | Disposal Method | Owner |
|---|
103. Confidentiality Evidence Matrix
Section titled “103. Confidentiality Evidence Matrix”Create:
08 Confidentiality Evidence MatrixUse:
| Control | Evidence | Source | Frequency | Owner |
|---|
104. Evidence — Classification
Section titled “104. Evidence — Classification”Examples:
Classification Policy
Classification Register
Data Labels105. Evidence — Access
Section titled “105. Evidence — Access”Examples:
Access Population
Approvals
Access Reviews
Permission Reports106. Evidence — Encryption
Section titled “106. Evidence — Encryption”Examples:
Encryption Configuration
TLS Configuration
Key Policy
Encryption Coverage107. Evidence — Sharing
Section titled “107. Evidence — Sharing”Examples:
Sharing Logs
Approval Records
External User Report
DLP Alerts108. Evidence — Third Parties
Section titled “108. Evidence — Third Parties”Examples:
Vendor Risk Assessment
SOC 2
Contract
DPA
Subprocessor Review109. Evidence — Retention
Section titled “109. Evidence — Retention”Examples:
Retention Schedule
System Settings
Deletion Logs110. Confidentiality Control Testing
Section titled “110. Confidentiality Control Testing”For each control define:
Requirement
Population
Sample
Evidence
Test
Exceptions
Conclusion111. Test Classification
Section titled “111. Test Classification”Select confidential datasets.
Verify:
Classification Assigned
Owner Assigned
Handling Requirement Defined112. Test Data Inventory
Section titled “112. Test Data Inventory”Compare:
Known Confidential Repositoriesagainst:
Asset / Cloud / SaaS DiscoveryIdentify missing systems.
113. Test Access
Section titled “113. Test Access”For selected repositories:
Identify Users
Review Business Need
Review Approval
Verify Least Privilege114. Test Access Reviews
Section titled “114. Test Access Reviews”Select review periods.
Verify:
Complete Population
Data Owner Review
Decisions
Removed Access115. Test Encryption at Rest
Section titled “115. Test Encryption at Rest”Population:
Confidential Data StoresVerify:
Encryption Enabled
Approved Method
Exception?116. Test Encryption in Transit
Section titled “116. Test Encryption in Transit”Review:
Web Traffic
APIs
File Transfers
Administrative ConnectionsVerify approved encrypted protocols.
117. Test Key Management
Section titled “117. Test Key Management”Sample:
Encryption KeysVerify:
Owner
Access
Rotation
Logging118. Test External Sharing
Section titled “118. Test External Sharing”Sample externally shared confidential information.
Verify:
Business Need
Approval
Recipient
Secure Method119. Test Vendor Confidentiality
Section titled “119. Test Vendor Confidentiality”For providers receiving confidential information verify:
Risk Assessment
Contract
Security Assurance
Current Need120. Test Retention
Section titled “120. Test Retention”Sample confidential datasets.
Compare:
Retention PolicyvsActual Configuration121. Test Disposal
Section titled “121. Test Disposal”Select completed deletion events.
Verify:
Request
Approval
Deletion
Evidence122. Test Confidentiality Monitoring
Section titled “122. Test Confidentiality Monitoring”Sample:
DLP Alerts
Bulk Downloads
Public Sharing EventsTrace:
Detection ↓Investigation ↓Closure123. Design Effectiveness
Section titled “123. Design Effectiveness”Ask:
If this confidentiality control operates as designed, will it reasonably protect the information from unauthorized disclosure?
Example:
Risk:
Source Code ExposureControl:
Employees are asked not to share code.This may be insufficient.
A stronger design:
Restricted Repository Access+MFA+Logging+External Sharing Controls124. Operating Effectiveness
Section titled “124. Operating Effectiveness”Example:
Control:
Quarterly Confidential Repository Access ReviewExpected:
4 ReviewsActual:
Q1 ✓Q2 ✓Q3 ✗Q4 ✓Result:
Partially Effective125. Complete Population Testing
Section titled “125. Complete Population Testing”Automated tools may enable testing:
100% Encryption Coverage
100% Public Sharing
100% Repository Access
100% External Guests126. Sampling Manual Controls
Section titled “126. Sampling Manual Controls”Manual controls may include:
Data Classification
External Sharing Approvals
Vendor Reviews
Deletion Approvals127. Confidentiality Finding — Access
Section titled “127. Confidentiality Finding — Access”Five former contractors retained access to a Confidential source-code repository beyond their approved engagement period.
Risk:
Unauthorized Disclosure
Source Code Theft128. Confidentiality Finding — Encryption
Section titled “128. Confidentiality Finding — Encryption”Two production data stores containing Confidential customer information were not encrypted according to the Data Protection Standard.
129. Confidentiality Finding — Sharing
Section titled “129. Confidentiality Finding — Sharing”Four Confidential documents were accessible through anonymous public-sharing links without approved exceptions.
130. Confidentiality Finding — Retention
Section titled “130. Confidentiality Finding — Retention”Customer exports containing Confidential information remained in temporary cloud storage beyond the approved 30-day retention period.
131. Confidentiality Finding — Vendor
Section titled “131. Confidentiality Finding — Vendor”A third-party analytics provider receives Confidential customer information but has not undergone the required annual security reassessment.
132. Root Cause Analysis — Public Sharing
Section titled “132. Root Cause Analysis — Public Sharing”Example:
Public Link Created ↓Platform Allows Anonymous Sharing ↓Default Setting Enabled ↓No Enterprise Sharing BaselineRoot cause:
The collaboration platform does not enforce an enterprise baseline restricting anonymous external sharing.
133. Correction
Section titled “133. Correction”Disable Existing Public Links134. Corrective Action
Section titled “134. Corrective Action”Disable Anonymous Sharing by Default +Require Approved Exception +Monitor Public Links135. Confidentiality Exceptions
Section titled “135. Confidentiality Exceptions”Example requirement:
Restricted Data→ Customer-Managed Encryption KeyLegacy SaaS:
Only Provider-Managed EncryptionException should include:
Risk
Business Need
Alternative Controls
Approval
Expiry
Migration Plan136. Confidentiality Dashboard
Section titled “136. Confidentiality Dashboard”Useful metrics include:
Confidential Data Inventory Coverage
Encryption Coverage
Confidential Access Review Completion
Public Sharing Links
Open DLP Incidents
Third-Party Assessment Coverage
Overdue Data Deletion137. Example Dashboard
Section titled “137. Example Dashboard”| Metric | Target | Current |
|---|---|---|
| Confidential Data Inventory | 100% | 97% |
| Encryption Coverage | 100% | 99% |
| Access Review Completion | 100% | 96% |
| Unauthorized Public Links | 0 | 3 |
| Current Critical Vendor Reviews | 100% | 94% |
138. Confidentiality KPI
Section titled “138. Confidentiality KPI”Example:
KPI:Percentage of Confidential data storesmeeting required protection controls139. Confidentiality KRI
Section titled “139. Confidentiality KRI”Example:
KRI:Number of unauthorized public-sharing eventsinvolving Confidential informationTolerance:
0140. Encryption KRI
Section titled “140. Encryption KRI”Example:
Confidential data storeswithout approved encryptionTolerance:
0141. Retention KRI
Section titled “141. Retention KRI”Example:
Confidential datasetspast approved deletion date142. Audit Walkthrough — Data Classification
Section titled “142. Audit Walkthrough — Data Classification”Auditor selects:
Customer Contract RepositoryTrace:
Owner ↓Classification ↓Access ↓Encryption ↓Retention143. Audit Walkthrough — Confidential Access
Section titled “143. Audit Walkthrough — Confidential Access”Auditor selects:
Source Code RepositoryVerify:
Authorized Users
MFA
Role
Latest Access Review
External Users144. Audit Walkthrough — Encryption
Section titled “144. Audit Walkthrough — Encryption”Auditor selects:
Customer DatabaseReview:
Data Classification
Encryption Configuration
Key Model
Key Access145. Audit Walkthrough — External Sharing
Section titled “145. Audit Walkthrough — External Sharing”Auditor selects:
Confidential Document Shared With VendorReview:
Purpose
Approval
Recipient
Secure Transfer
Contract146. Audit Walkthrough — Retention
Section titled “146. Audit Walkthrough — Retention”Auditor selects:
Expired Customer ExportVerify:
Retention Requirement
Deletion Trigger
Deletion Evidence147. Common Confidentiality Mistakes
Section titled “147. Common Confidentiality Mistakes”Mistake 1 — Everything Classified Confidential
Section titled “Mistake 1 — Everything Classified Confidential”Classification loses value.
Mistake 2 — Confidentiality Equals Encryption
Section titled “Mistake 2 — Confidentiality Equals Encryption”Access, sharing, retention, and disposal are ignored.
Mistake 3 — Data Inventory Incomplete
Section titled “Mistake 3 — Data Inventory Incomplete”Unknown repositories remain unprotected.
Mistake 4 — Business Users Have Excessive Access
Section titled “Mistake 4 — Business Users Have Excessive Access”Need-to-know is not enforced.
Mistake 5 — Administrators Ignored
Section titled “Mistake 5 — Administrators Ignored”Technical privileged access remains unrestricted.
Mistake 6 — Encryption Enabled but Keys Poorly Protected
Section titled “Mistake 6 — Encryption Enabled but Keys Poorly Protected”Cryptographic control is weakened.
Mistake 7 — Public Sharing Not Monitored
Section titled “Mistake 7 — Public Sharing Not Monitored”SaaS creates hidden disclosure risk.
Mistake 8 — Vendors Receive More Data Than Necessary
Section titled “Mistake 8 — Vendors Receive More Data Than Necessary”Third-party exposure increases.
Mistake 9 — Retention Defined but Not Enforced
Section titled “Mistake 9 — Retention Defined but Not Enforced”Confidential information remains indefinitely.
Mistake 10 — Deletion Means Primary Database Only
Section titled “Mistake 10 — Deletion Means Primary Database Only”Backups and replicas are ignored.
148. Weak Confidentiality Model
Section titled “148. Weak Confidentiality Model”Sensitive Data ↓Encryption Enabled ↓Assume Protected149. Strong Confidentiality Model
Section titled “149. Strong Confidentiality Model”Identify ↓Classify ↓Assign Owner ↓Restrict Access ↓Encrypt ↓Monitor ↓Control Sharing ↓Govern Third Parties ↓Retain ↓Securely Dispose ↓Evidence150. Practical Activity — Build Confidentiality Control Matrix
Section titled “150. Practical Activity — Build Confidentiality Control Matrix”Create:
01 Confidentiality Control MatrixInclude at least 15 controls across:
Classification
Inventory
IAM
Encryption
Key Management
Sharing
Third Parties
Retention
Disposal
Monitoring151. Practical Activity — Build Data Classification Register
Section titled “151. Practical Activity — Build Data Classification Register”Create:
02 Data Classification RegisterAdd at least 15 fictional data assets.
Use:
| Data Asset | Owner | Classification | Handling Requirement |
|---|
152. Practical Activity — Build Confidential Data Inventory
Section titled “152. Practical Activity — Build Confidential Data Inventory”Create:
03 Confidential Data InventoryInclude:
Database
Cloud Storage
SaaS
Source Repository
Email
Backup153. Practical Activity — Build Encryption Evidence Register
Section titled “153. Practical Activity — Build Encryption Evidence Register”Create:
04 Encryption Evidence RegisterUse:
| System | Data | At Rest | In Transit | Key Owner | Status |
|---|
154. Practical Activity — Build Confidential Sharing Register
Section titled “154. Practical Activity — Build Confidential Sharing Register”Create:
05 Confidential Data Sharing RegisterAdd internal and external sharing examples.
Track:
Recipient
Purpose
Approval
Method
Expiry155. Practical Activity — Build Retention & Disposal Register
Section titled “155. Practical Activity — Build Retention & Disposal Register”Create:
06 Retention & Disposal RegisterInclude at least ten data categories.
156. Practical Activity — Build Confidentiality Evidence Matrix
Section titled “156. Practical Activity — Build Confidentiality Evidence Matrix”Create:
07 Confidentiality Evidence MatrixMap evidence for:
Classification
Access
Encryption
Key Management
Sharing
Vendor Risk
Retention
Deletion157. Practical Activity — Build Confidentiality Control Testing Checklist
Section titled “157. Practical Activity — Build Confidentiality Control Testing Checklist”Create:
08 Confidentiality Control Testing ChecklistTest:
Classification
Data Inventory
Confidential Access
Access Review
Encryption at Rest
Encryption in Transit
Key Access
External Sharing
Vendor Confidentiality
Retention
Secure Disposal
Monitoring158. Confidentiality Readiness Checklist
Section titled “158. Confidentiality Readiness Checklist”Governance
Section titled “Governance”-
Classification policy established.
-
Confidentiality responsibilities defined.
-
Data owners assigned.
-
Handling requirements documented.
Inventory
Section titled “Inventory”-
Confidential data identified.
-
Systems documented.
-
SaaS included.
-
Backups included.
-
Third parties included.
Access
Section titled “Access”-
Need-to-know implemented.
-
Least privilege implemented.
-
Access requires approval.
-
Privileged access governed.
-
Access reviews performed.
-
External users reviewed.
Encryption
Section titled “Encryption”-
Encryption requirements defined.
-
Data at rest encrypted.
-
Data in transit encrypted.
-
Key ownership defined.
-
Key access restricted.
-
Rotation requirements defined.
Sharing
Section titled “Sharing”-
Internal sharing controlled.
-
External sharing controlled.
-
Public links governed.
-
Secure transfer methods defined.
-
Sharing evidence available.
Third Parties
Section titled “Third Parties”-
Providers identified.
-
Vendor assessments performed.
-
Confidentiality clauses established.
-
Subprocessors considered.
-
Data minimization applied.
Retention
Section titled “Retention”-
Retention schedules defined.
-
System settings aligned.
-
Legal holds supported.
-
Expired data identified.
Disposal
Section titled “Disposal”-
Deletion procedures defined.
-
Physical media disposal defined.
-
SaaS deletion addressed.
-
Cloud backups considered.
-
Evidence retained.
Monitoring
Section titled “Monitoring”-
Sensitive access logged.
-
External sharing monitored.
-
DLP used where appropriate.
-
Incidents investigated.
-
Confidentiality metrics reported.
159. GRC Analyst Responsibilities
Section titled “159. GRC Analyst Responsibilities”A GRC professional supporting SOC 2 Confidentiality may:
-
Maintain classification policies.
-
Maintain confidential-data inventories.
-
Coordinate data ownership.
-
Map confidentiality risks to controls.
-
Review access-control evidence.
-
Review encryption evidence.
-
Review key-management controls.
-
Review external data-sharing processes.
-
Assess third-party confidentiality.
-
Review retention requirements.
-
Review disposal evidence.
-
Test confidentiality controls.
-
Document exceptions.
-
Facilitate root-cause analysis.
-
Track remediation.
-
Maintain confidentiality dashboards.
-
Support external SOC auditors.
GRC connects:
Data Owners
Security
IAM
Cloud
Engineering
Legal
Procurement
Privacy
Vendors
Auditors160. Confidentiality Maturity Model
Section titled “160. Confidentiality Maturity Model”Level 1 — Informal
Section titled “Level 1 — Informal”Sensitive Data Existsbut is not consistently classified.Level 2 — Defined
Section titled “Level 2 — Defined”Classification
Access
EncryptionLevel 3 — Governed
Section titled “Level 3 — Governed”Inventory
Owners
Sharing
Retention
Vendor ControlsLevel 4 — Integrated
Section titled “Level 4 — Integrated”Automated Classification
DLP
Continuous Access Monitoring
EvidenceLevel 5 — Continuous Confidentiality Assurance
Section titled “Level 5 — Continuous Confidentiality Assurance”Data Discovery
Dynamic Classification
Continuous Sharing Monitoring
Automated Retention
Continuous Control Testing161. Confidentiality Mindset
Section titled “161. Confidentiality Mindset”For every confidential information asset ask:
What information is this?
Why is it confidential?
Who owns it?
Where is it stored?
Who can access it?
Who has privileged access?
Is access still required?
Is it encrypted?
Who controls the keys?
How is it transmitted?
Can users share it externally?
Which third parties receive it?
How long should it be retained?
How is it deleted?
What happens to backups?
Are material access and sharing events monitored?
What evidence proves each control?If these questions can be answered, Confidentiality becomes a practical lifecycle rather than simply an encryption requirement.
Key Takeaways
Section titled “Key Takeaways”-
Confidentiality protects information designated as confidential from unauthorized disclosure.
-
Confidentiality and Privacy are related but distinct.
-
Data classification provides the foundation for proportionate protection.
-
Organizations should know where confidential information is stored and processed.
-
Data owners should help define classification, access, sharing, and retention requirements.
-
Need-to-know and least privilege are important confidentiality principles.
-
Privileged and service-account access should be included in confidentiality governance.
-
Encryption should protect confidential information at rest and in transit where required.
-
Key management is essential to effective cryptographic protection.
-
Secure sharing requires authorized recipients, valid purpose, approved methods, and appropriate controls.
-
Third parties and subprocessors can extend the confidentiality boundary.
-
Retention should limit how long confidential information remains exposed.
-
Secure disposal should include cloud copies, backups, SaaS, and physical media where relevant.
-
Monitoring can detect bulk access, public sharing, DLP events, and other disclosure risks.
-
SOC 2 confidentiality assurance requires controls, evidence, testing, findings, and remediation across the information lifecycle.
Knowledge Check
Section titled “Knowledge Check”Before continuing, make sure you can answer:
-
What does the SOC 2 Confidentiality category address?
-
How does Confidentiality differ from Security?
-
How does Confidentiality differ from Privacy?
-
Why is information classification important?
-
What should a confidential-data inventory contain?
-
What is the need-to-know principle?
-
Why should privileged access be included?
-
Why are service accounts relevant?
-
What does encryption at rest protect?
-
Why is encryption in transit important?
-
Why is key management critical?
-
What risks exist with external sharing?
-
How can DLP support confidentiality?
-
Why should third parties be included?
-
What is data minimization?
-
Why should retention be controlled?
-
What should secure disposal address?
-
Why are cloud backups relevant to deletion?
-
What evidence can support Confidentiality controls?
-
What role does GRC play in SOC 2 Confidentiality?
What’s Next?
Section titled “What’s Next?”➡️ Next: 09 — Privacy
In the next lesson, you will move from protecting information designated as confidential into governing personal information throughout its complete lifecycle.
You will work through:
Privacy Governance ↓Privacy Notice ↓Collection ↓Choice & Consent ↓Purpose Limitation ↓Use ↓Data Minimization ↓Access & Individual Rights ↓Disclosure ↓Retention ↓Deletion ↓Privacy Incidents ↓Monitoring & EvidenceYou will also build practical SOC 2 artifacts including a Privacy Control Matrix, PII Inventory, Processing Purpose Register, Consent Register, Data Subject Request Register, Third-Party PII Sharing Register, Privacy Retention Register, and Privacy Control Testing Checklist.