EMZETT.
Login

CIA Triad

In short: The three core goals of information security: confidentiality, integrity and availability.

In more detail: Every security measure serves at least one of these three goals. The abbreviation CIA has nothing to do with the intelligence agency.

In Depth

The three goals

  • Confidentiality: only authorised people may read data. Means: encryption, access rights, multi-factor authentication.
  • Integrity: data stays unchanged and correct. Means: hashing, digital signatures, checksums. See integrity.
  • Availability: systems and data are accessible when needed. Means: backups, redundancy, protection against DDoS.

Examples of violations

A stolen password violates confidentiality. A manipulated account balance violates integrity. A ransomware attack that takes servers down violates availability.

Extensions

Authenticity and non-repudiation are often added (see authenticity). In practice it is always a trade-off: more confidentiality often makes processes slower and limits availability.

See also: Integrity, Authenticity, Encryption, Cybersecurity