2 minutes estimated reading time.

Non-Repudiation in Cybersecurity

Non-repudiation is a foundational security property among the five pillars of Information Assurance. It is at natural odds with Privacy and must be balanced.

By — Published 09/16/2026

A presentation slide from Rietta's Practical Application Security Course, showing the CIANA pillars. One callout points to non-repudiation explaining it's the who, what, when, and where pillar.
A presentation slide from Rietta's Practical Application Security Course, showing the CIANA pillars. One callout points to non-repudiation explaining it's the who, what, when, and where pillar. © 2025 Rietta Inc.

Non-repudiation is the among the five foundational security properties in the five pillars of information assurance, CIANA (a superset of the CIA Triad):

  • Confidentiality
  • Integrity
  • Availability
  • Non-repudiation
  • Authentication [& Access Control]

In my lecture content, I often call this the one of the “log more things” properties. The idea is to log the who, what, when, and where access occurs. When properly implemented a non-repudiation control should allow you to not only know who did an action but also prove that another party did not do it instead. Just logging all the things is not a panacea and brings a risk of accidentally storing private data in plain text when logging is done carelessly.

This principle is at odds with the Privacy-centric principle of repudiation. Basically, we don’t want to leak what library books you are checking out.

Regulations force a balance, including the:

  • EU General Data Protection Regulation (GDPR)
  • California Consumer Privacy Act (CCPA)
  • HIPAA Privacy Rule
  • Other contracts and industry norms

When two principles are at odds, they must often be balanced. While the privacy of a person using a website is important, the privacy of the people who’s information is protected/processed by that website also matters. Sufficient logging and monitoring is among the OWASP Top 10 for good reason. If you build on Rails, I’ve also recorded a talk on designing for security, privacy, and consent under GDPR.