1. National Institute of Standards and Technology (NIST). (2020). Special Publication (SP) 800-53 Rev. 5
Security and Privacy Controls for Information Systems and Organizations. Page 231 (Appendix F). Retrieved from https://doi.org/10.6028/NIST.SP.800-53r5. The document defines Confidentiality as "Preserving authorized restrictions on information access and disclosure
including means for protecting personal privacy and proprietary information."
2. Shirey
R. (2007). RFC 4949
Internet Security Glossary
Version 2. The Internet Society. Retrieved from https://doi.org/10.17487/RFC4949.
Page 61 defines Confidentiality as "The property that information is not made available or disclosed to unauthorized individuals
entities
or processes."
Page 213 defines a passive attack as an attack where the goal is to "obtain information that is being transmitted
" directly linking it to a breach of confidentiality.
3. Saltzer
J. H.
& Schroeder
M. D. (1975). The Protection of Information in Computer Systems. Proceedings of the IEEE
63(9)
1278–1308. https://doi.org/10.1109/PROC.1975.9939. This foundational academic paper discusses the principle of Confidentiality (referred to as secrecy) as a primary goal in information protection
distinct from integrity and availability.