1.2 CIA Triad & Security Concepts

Security Fundamentals

The CIA Triad at a glance

The CIA Triad describes three fundamental objectives that information security controls are designed to protect.

šŸ”’

Confidentiality

Prevent unauthorised disclosure of information.

Who can SEE it?
āœ“

Integrity

Protect information from unauthorised or improper modification.

Can I TRUST it?
⚔

Availability

Ensure authorised users can access systems and information when required.

Can I REACH it?

Why the CIA Triad matters

Security is not simply about preventing attackers from stealing information. An organisation can suffer serious harm even when no confidential information is disclosed.

IncidentPrimary objective affected
Customer data is stolenConfidentiality
Financial records are alteredIntegrity
An online service becomes unavailableAvailability
Three useful questions

Who should be able to see this information?

How do we know it has not been changed improperly?

Will authorised users be able to access it when they need it?

1 Confidentiality Prevent unauthorised disclosure

What is confidentiality?

Confidentiality means ensuring that information is accessible only to authorised individuals, processes or systems.

It applies to information stored on devices and databases, transmitted across networks, processed by applications, printed on paper, discussed verbally, stored in backups and held by third parties.

Examples of confidential information

Passwords Authentication tokens Customer records Medical records Payment-card information Bank details Employee records Intellectual property Cryptographic keys

Common threats

  • Credential theft — stolen credentials are used to access information.
  • Phishing — users are manipulated into revealing credentials or sensitive data.
  • Excessive permissions — users can access information they do not require.
  • Network interception — information is captured while travelling across an insecure network.
  • Misconfigured cloud storage — sensitive information is accidentally exposed publicly.
  • Lost devices — laptops or phones containing sensitive information are lost or stolen.
  • Insider threats — an authorised person deliberately misuses access.
  • Shoulder surfing — someone observes confidential information or credentials.

Controls that protect confidentiality

Encryption

Protects data at rest and data in transit.

Authentication

Establishes the identity of a user or system.

Authorisation

Determines what an authenticated identity may access.

Least privilege

Provides only the permissions required to perform a function.

Need-to-know

Restricts access to information genuinely required for a role.

Data classification

Applies protection according to information sensitivity.

DLP

Helps detect and prevent inappropriate disclosure of sensitive information.

Example

An attacker downloads an employee database containing salaries, addresses and bank details. The records are not changed and the database remains available.

Primary impact: Loss of confidentiality.
2 Integrity Keep information accurate and trustworthy

What is integrity?

Integrity means protecting information and systems from unauthorised or improper modification or destruction.

Information should remain:

Accurate Complete Consistent Trustworthy
Important

Integrity violations are not always caused by attackers. Software bugs, human error, hardware failure, database corruption and incorrect configuration can also damage integrity.

Common threats

  • Malware — alters files or configurations.
  • SQL injection — manipulates database information.
  • Man-in-the-middle attacks — intercept and alter communications.
  • Privilege abuse — authorised access is deliberately misused.
  • Configuration errors — critical settings are accidentally modified.
  • Supply-chain compromise — malicious changes are introduced into legitimate software.

Controls that protect integrity

Hashing

Helps identify whether information has changed.

Digital signatures

Support integrity and authentication of signed information.

File Integrity Monitoring

Detects unexpected modifications to important files.

Access control

Limits who is permitted to modify information.

Change management

Ensures modifications are authorised, tested and documented.

Version control

Records who changed information, what changed and when.

Backups

Can restore known-good information after corruption or malicious modification.

Example

An attacker changes the bank account number shown on a company's invoices so customers send payments to the attacker.

Primary impact: Loss of integrity.
3 Availability Ensure systems and information can be accessed when required

What is availability?

Availability means ensuring that authorised users can access systems, services and information when required.

It is especially important for hospitals, emergency services, financial systems, telecommunications, transport systems, industrial control environments and cloud services.

Common threats

  • DoS and DDoS attacks — overwhelm systems or network connections.
  • Ransomware — prevents legitimate access to systems or information.
  • Hardware failure — components such as disks and network equipment fail.
  • Power outage — infrastructure loses electrical power.
  • Natural disasters — fire, flood or severe weather damages systems.
  • Human error — accidental deletion or misconfiguration causes an outage.
  • Capacity problems — legitimate demand overwhelms insufficient infrastructure.

Controls that protect availability

Redundancy

Duplicates critical components to reduce single points of failure.

High availability

Architectures designed to minimise service interruption.

Load balancing

Distributes demand across multiple systems.

Backups

Allow information to be restored after loss or corruption.

Disaster recovery

Provides procedures and technology for restoring systems after major disruption.

Business continuity

Supports continued delivery of critical business functions.

DDoS protection

Helps filter or absorb malicious traffic.

Monitoring

Detects failures and degradation before they become major outages.

Example

A DDoS attack prevents customers from accessing a company's website for six hours. No data is stolen or modified.

Primary impact: Loss of availability.

One incident can affect several objectives

Real-world incidents do not always fit neatly into one category. Ransomware is a good example.

Confidentiality

Information may be stolen before encryption.

Integrity

Files may be modified or encrypted.

Availability

Users may no longer be able to access systems.

āš–ļø Balancing confidentiality, integrity and availability Different systems have different priorities

Security decisions frequently involve trade-offs. The correct balance depends on business requirements, risk, information sensitivity, regulation, operational requirements and safety.

šŸ¦ Online banking

Confidentiality: customers must not see each other's information.

Integrity: transactions and balances must be accurate.

Availability: customers require reliable access to banking services.

šŸ“° Public news website

Published articles are public, so confidentiality may be relatively low.

Integrity remains important because attackers must not be able to alter stories.

Availability matters because readers need to reach the website.

šŸ„ Emergency medical system

Availability may receive particularly high priority because disruption could directly affect patient safety.

šŸ“Š CIA Triad and risk assessment Use the model to assess potential impact

For each asset, ask:

Confidentiality

What would happen if unauthorised people obtained this information?

Integrity

What would happen if this information became inaccurate or maliciously altered?

Availability

What would happen if this system or information became unavailable?

AssetCIA
Public marketing websiteLowHighMedium
Payroll databaseHighHighMedium
Emergency medical systemHighHighVery High
šŸ›”ļø Which security controls protect C, I and A? Many controls support more than one objective
ControlCIA
Encryptionāœ“
Access controlāœ“āœ“
Hashingāœ“
Digital signaturesāœ“
Backupsāœ“āœ“
Redundant serversāœ“
DDoS protectionāœ“
Multifactor authenticationāœ“āœ“
File integrity monitoringāœ“
Data Loss Preventionāœ“

This table is deliberately simplified. The effect of a control depends on how and why it is implemented.

āž• Related security concepts Beyond the traditional CIA Triad
Authenticity

Confidence that a user, system, message or piece of information is genuine.

Accountability

The ability to associate actions with a particular user or entity.

Non-repudiation

Evidence that makes it difficult for an individual to deny performing an action.

Privacy

The appropriate collection, processing, storage and use of personal information.

The opposite: the DAD Triad

A useful way to remember CIA is to consider what an attacker might try to achieve.

šŸ”’ Confidentiality ↔ Disclosure
āœ“ Integrity ↔ Alteration
⚔ Availability ↔ Destruction / Denial
āš ļø Common mistakes Easy distinctions to get wrong
Encryption automatically provides integrity

Encryption primarily protects confidentiality. Some cryptographic mechanisms provide integrity as well, but encryption alone should not automatically be treated as an integrity control.

Integrity means secrecy

Integrity concerns accuracy and unauthorised modification. Confidentiality concerns unauthorised disclosure.

Availability simply means "online"

Authorised users must be able to access a service reliably and within acceptable timescales.

Every control maps to only one objective

Many controls support several objectives. Backups, for example, can support both integrity and availability.

CISSP Exam Perspective

Look at what actually happened to the asset

šŸ”’ Confidentiality clues

Exposed Disclosed Leaked Intercepted Stolen Viewed

āœ“ Integrity clues

Modified Manipulated Corrupted Altered Falsified Tampered

⚔ Availability clues

Inaccessible Offline Unavailable Disrupted Destroyed Overwhelmed

Quick memory aid

Confidentiality Who can SEE it?
Integrity Can I TRUST it?
Availability Can I REACH it?

Secret. Correct. Available.

Key takeaways

Confidentiality protects information from unauthorised disclosure.

Integrity protects information and systems from unauthorised or improper modification.

Availability ensures authorised users can access information and services when required.

Effective security is rarely about maximising one objective at all costs. The correct balance depends on the needs and risks of the organisation.