information
So you have had a chance to ponder the complications that come from the idea we, generally speaking, want confidentiality.
Pick a system, any system that you think you know reasonably well. If you’re stumped, try the obvious – your bank, your doctor or dentist. If you’re feeling creative, how about your local library, or your dry cleaner.
Zero: Describe the system (briefly!). As in: I’m going to talk about the _____ system, which does this, that and the other thing.
First: When we talk about confidentiality, we’re talking about un authorized access to information. That means there is (or at least probably is) authorized access to information. For your system, what roles or people are there with authorized access – and what information can they see or use. Is there anything special about their roles or their level of access? Are there exceptions?
Second: What (briefly) is the worst possible scenario you can think of for a confidentiality failure/breach? What repercussions or impacts are there?
Third: How – in technical or other terms – could (or can) you improve the security of the situation? What measures or technologies would make sense? Why?