1.2 CIA Triad & Security Concepts
The CIA Triad at a glance
The CIA Triad describes three fundamental objectives that information security controls are designed to protect.
Confidentiality
Prevent unauthorised disclosure of information.
Who can SEE it?Integrity
Protect information from unauthorised or improper modification.
Can I TRUST it?Availability
Ensure authorised users can access systems and information when required.
Can I REACH it?Why the CIA Triad matters
Security is not simply about preventing attackers from stealing information. An organisation can suffer serious harm even when no confidential information is disclosed.
| Incident | Primary objective affected |
|---|---|
| Customer data is stolen | Confidentiality |
| Financial records are altered | Integrity |
| An online service becomes unavailable | Availability |
Who should be able to see this information?
How do we know it has not been changed improperly?
Will authorised users be able to access it when they need it?
1 Confidentiality Prevent unauthorised disclosure
What is confidentiality?
Confidentiality means ensuring that information is accessible only to authorised individuals, processes or systems.
It applies to information stored on devices and databases, transmitted across networks, processed by applications, printed on paper, discussed verbally, stored in backups and held by third parties.
Examples of confidential information
Common threats
- Credential theft ā stolen credentials are used to access information.
- Phishing ā users are manipulated into revealing credentials or sensitive data.
- Excessive permissions ā users can access information they do not require.
- Network interception ā information is captured while travelling across an insecure network.
- Misconfigured cloud storage ā sensitive information is accidentally exposed publicly.
- Lost devices ā laptops or phones containing sensitive information are lost or stolen.
- Insider threats ā an authorised person deliberately misuses access.
- Shoulder surfing ā someone observes confidential information or credentials.
Controls that protect confidentiality
Protects data at rest and data in transit.
Establishes the identity of a user or system.
Determines what an authenticated identity may access.
Provides only the permissions required to perform a function.
Restricts access to information genuinely required for a role.
Applies protection according to information sensitivity.
Helps detect and prevent inappropriate disclosure of sensitive information.
An attacker downloads an employee database containing salaries, addresses and bank details. The records are not changed and the database remains available.
Primary impact: Loss of confidentiality.2 Integrity Keep information accurate and trustworthy
What is integrity?
Integrity means protecting information and systems from unauthorised or improper modification or destruction.
Information should remain:
Integrity violations are not always caused by attackers. Software bugs, human error, hardware failure, database corruption and incorrect configuration can also damage integrity.
Common threats
- Malware ā alters files or configurations.
- SQL injection ā manipulates database information.
- Man-in-the-middle attacks ā intercept and alter communications.
- Privilege abuse ā authorised access is deliberately misused.
- Configuration errors ā critical settings are accidentally modified.
- Supply-chain compromise ā malicious changes are introduced into legitimate software.
Controls that protect integrity
Helps identify whether information has changed.
Support integrity and authentication of signed information.
Detects unexpected modifications to important files.
Limits who is permitted to modify information.
Ensures modifications are authorised, tested and documented.
Records who changed information, what changed and when.
Can restore known-good information after corruption or malicious modification.
An attacker changes the bank account number shown on a company's invoices so customers send payments to the attacker.
Primary impact: Loss of integrity.3 Availability Ensure systems and information can be accessed when required
What is availability?
Availability means ensuring that authorised users can access systems, services and information when required.
It is especially important for hospitals, emergency services, financial systems, telecommunications, transport systems, industrial control environments and cloud services.
Common threats
- DoS and DDoS attacks ā overwhelm systems or network connections.
- Ransomware ā prevents legitimate access to systems or information.
- Hardware failure ā components such as disks and network equipment fail.
- Power outage ā infrastructure loses electrical power.
- Natural disasters ā fire, flood or severe weather damages systems.
- Human error ā accidental deletion or misconfiguration causes an outage.
- Capacity problems ā legitimate demand overwhelms insufficient infrastructure.
Controls that protect availability
Duplicates critical components to reduce single points of failure.
Architectures designed to minimise service interruption.
Distributes demand across multiple systems.
Allow information to be restored after loss or corruption.
Provides procedures and technology for restoring systems after major disruption.
Supports continued delivery of critical business functions.
Helps filter or absorb malicious traffic.
Detects failures and degradation before they become major outages.
A DDoS attack prevents customers from accessing a company's website for six hours. No data is stolen or modified.
Primary impact: Loss of availability.One incident can affect several objectives
Real-world incidents do not always fit neatly into one category. Ransomware is a good example.
Information may be stolen before encryption.
Files may be modified or encrypted.
Users may no longer be able to access systems.
āļø Balancing confidentiality, integrity and availability Different systems have different priorities
Security decisions frequently involve trade-offs. The correct balance depends on business requirements, risk, information sensitivity, regulation, operational requirements and safety.
š¦ Online banking
Confidentiality: customers must not see each other's information.
Integrity: transactions and balances must be accurate.
Availability: customers require reliable access to banking services.
š° Public news website
Published articles are public, so confidentiality may be relatively low.
Integrity remains important because attackers must not be able to alter stories.
Availability matters because readers need to reach the website.
š„ Emergency medical system
Availability may receive particularly high priority because disruption could directly affect patient safety.
š CIA Triad and risk assessment Use the model to assess potential impact
For each asset, ask:
What would happen if unauthorised people obtained this information?
What would happen if this information became inaccurate or maliciously altered?
What would happen if this system or information became unavailable?
| Asset | C | I | A |
|---|---|---|---|
| Public marketing website | Low | High | Medium |
| Payroll database | High | High | Medium |
| Emergency medical system | High | High | Very High |
š”ļø Which security controls protect C, I and A? Many controls support more than one objective
| Control | C | I | A |
|---|---|---|---|
| Encryption | ā | ||
| Access control | ā | ā | |
| Hashing | ā | ||
| Digital signatures | ā | ||
| Backups | ā | ā | |
| Redundant servers | ā | ||
| DDoS protection | ā | ||
| Multifactor authentication | ā | ā | |
| File integrity monitoring | ā | ||
| Data Loss Prevention | ā |
This table is deliberately simplified. The effect of a control depends on how and why it is implemented.
ā Related security concepts Beyond the traditional CIA Triad
Confidence that a user, system, message or piece of information is genuine.
The ability to associate actions with a particular user or entity.
Evidence that makes it difficult for an individual to deny performing an action.
The appropriate collection, processing, storage and use of personal information.
The opposite: the DAD Triad
A useful way to remember CIA is to consider what an attacker might try to achieve.
ā ļø Common mistakes Easy distinctions to get wrong
Encryption primarily protects confidentiality. Some cryptographic mechanisms provide integrity as well, but encryption alone should not automatically be treated as an integrity control.
Integrity concerns accuracy and unauthorised modification. Confidentiality concerns unauthorised disclosure.
Authorised users must be able to access a service reliably and within acceptable timescales.
Many controls support several objectives. Backups, for example, can support both integrity and availability.
Look at what actually happened to the asset
š Confidentiality clues
ā Integrity clues
ā” Availability clues
Quick memory aid
Secret. Correct. Available.
Key takeaways
Confidentiality protects information from unauthorised disclosure.
Integrity protects information and systems from unauthorised or improper modification.
Availability ensures authorised users can access information and services when required.
Effective security is rarely about maximising one objective at all costs. The correct balance depends on the needs and risks of the organisation.
