Could you please help me to clarify the following:
ISO 25023 standard divided security into the following 5 characteristics which are:
Confidentiality characteristic (divided into) -----> Access controllability and Data encryption
Integrity characteristic (divided into) -----> Data corruption prevention and Internal data corruption prevention
Non-repudiation characteristic (divided into) -----> Utilization of digital signature
Accountability characteristic (divided into) -----> Access auditability and System Log keeping time
Authenticity characteristic (divided into) -----> Authentication protocols and Establishment of authentication rules
Based on the literature, authenticity is a part of confidentiality (access controllability), why ISO has separated it form confidentiality and categorized it as a characteristic?