Skip to main content

Disclosure

Disclosure in this context refers to the unauthorized access or exposure of information. It is the attacker’s counterpart to the defender’s confidentiality. An example would be a data breach in which sensitive customer data is leaked to the public or sold on the dark web. Disclosure-focused attacks aim to exfiltrate information without necessarily alerting the organization.

Alteration

An alteration is a modification of any kind of data or system without legitimate access or intention. Alteration represents the modification of data or systems, usually without detection. This is the attacker’s response to the integrity goal. An attacker might modify database entries, change file contents, or manipulate logs to cover their tracks. In some cases, the altered data can have devastating consequences, such as when medical records or financial transactions are tampered with.

Denial

Denial happens when the information or systems become unavailable to legitimate users for a period of time. This contrasts with the defender’s aim of availability. A typical example is a DDoS attack, which floods a website with traffic, making it unreachable by regular users. Denial can also occur when ransomware encrypts files and prevents access until a ransom is paid.