NCAE Mapping Hub
Security+ ยท 1.0 General Security Concepts

Non-repudiation

Cryptographic evidence that an actor performed an action, such that they cannot later credibly deny it. Typically provided by digital signatures + tamper-proof logs.

How this shows up at NCAE

Audit logs (`/var/log/auth.log`, `journalctl`) give weak non-repudiation at NCAE. if red team gets root, they can doctor them. AIDE and immutable log shipping would give stronger guarantees.