Reliable systems protect confidential information from unauthorized disclosure. Satisfying this principle requires first that management identify which information is confidential and needs to be protected. Confidential information includes sensitive data produced internally as well that shared by business partners Although each organization will develop its own definitions of what information it considers confidential, most definitions are likely to include the following examples listed in the Trust Services framework among the Types of information that need to be protected: business plans, pricing strategies, client and customer lists, and legal documents. Table 8-1 summarizes the key controls designed to protect confidentiality of information.