Cyber Risk Compendium

Non-repudiation (denial of actions)

BSI ID: G 0.37

People may deny having committed certain actions for various reasons, for example because these actions violate instructions, safety regulations or even laws. However, they may also deny having received a notification, for example because they forgot an appointment. In the field of information security, emphasis is therefore often placed on bindingness, a property that is intended to ensure that actions that have been performed cannot be denied without justification. In English-speaking countries, the term non-repudiation is used for this.

In communication, a further distinction is made between whether a communication participant denies receipt of a message (repudiation of receipt) or its transmission (repudiation of origin). Denying receipt of a message can be important in financial transactions, for example, if someone disputes that they received an invoice on time. Similarly, a communication participant may deny sending a message, e.g., disputing that an order was placed. The sending or receipt of messages can be denied in postal mail as well as in fax or email.

Example:

  • An urgently needed spare part is ordered electronically. After a week, a complaint is made about its non-delivery, and in the meantime, high costs have been incurred due to production downtime. The supplier denies having received an order.