TechKnowSurge
NIST NICE K1120 CompTIA Tech+ 6.1 Cisco CyberOps Associate 1.1 ISC2 CISSP 1.2 ISC2 CISSP 1.4 CompTIA Security+ 5.1 NIST CSF GV.OC-03 Cisco CCST Cybersecurity 5.3
VideoSecurityFree

The 5 Pillars of Information Security

Information security is a critical business priority, driven by rising cybercrime, tightening regulations, and growing customer expectations. This content covers the five pillars of information security — confidentiality, integrity, availability, authenticity, and non-repudiation — and the real-world consequences of failing to protect sensitive data.

Complete this video to capture a CTF flag worth 1 point.

About this video

The business case for information security has never been stronger. Cybercrime surged significantly in recent years, with high-profile breaches making headlines on a near-daily basis. In response, governments and regulatory bodies have introduced new laws to protect consumers and employees, while customers themselves are increasingly scrutinizing how organizations handle sensitive data before entering into contracts or business relationships. Cybersecurity insurance has also become a standard requirement, with insurers demanding demonstrable security practices before extending coverage. The consequences of inadequate information security can be severe and wide-ranging. Organizations may face financial losses, regulatory fines, expensive breach notification and remediation processes, and long-term damage to their competitive position and reputation. For small businesses in particular, a single cyberattack can be catastrophic — research indicates that 60% close within six months of a significant incident. To address these risks, information security professionals rely on a set of foundational principles. The well-established CIA Triad — confidentiality, integrity, and availability — defines the core objectives: keeping data accessible only to authorized users, ensuring it cannot be altered without authorization, and guaranteeing it remains accessible when needed. Expanding on this model, two additional pillars are recognized by frameworks such as the CISSP: authenticity, which verifies that information originates from a confirmed source, and non-repudiation, which ensures that neither the sender nor the recipient of information can deny their role in a transaction. Together, these five pillars provide a comprehensive framework for evaluating and building information security programs, with cryptography serving as a foundational enabler across all of them.

What you'll learn

What's covered

Information Security Fundamentals

Aligned to

NIST NICE
K1120 Knowledge of Confidentiality, Integrity, Availability, Authenticity, and Non-repudiation (CIAAN) principles and practices
CompTIA Tech+
6.1 Summarize confidentiality, integrity, and availability concerns
Cisco CyberOps Associate
1.1 Describe the CIA triad
ISC2 CISSP
1.2 Understand and apply security concepts
1.4 Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
CompTIA Security+
5.1 Summarize elements of effective security governance
NIST CSF
GV.OC-03 Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
Cisco CCST Cybersecurity
5.3 Explain the impact of compliance frameworks on incident handling

Key terms

Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Non-repudiation
The assurance that a party cannot deny having sent or received a message or performed an action.
CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Authenticity
The assurance that information or a communication originates from the claimed source and has not been fabricated or impersonated. Digital signatures and certificates are common mechanisms for establishing authenticity.
Cryptography
The practice of securing information by transforming it into an unreadable format using mathematical algorithms.

Topics

Information Security Confidentiality Integrity Availability Non Repudiation Authenticity Cybersecurity Compliance Data Protection

Transcript

If businesses nowadays don't secure their customers' information and their employees' information and other sensitive information, they won't stand a chance in today's business climate. Things are changing rapidly.

What's changing in today's climate

Cyber crime is on the rise, and through Co things drastically increased. Day after day in the news we saw different companies and different people being hacked. We just saw increased numbers from it, and that's caused a real problem in this IT field.

To help protect against cyber crime and other issues when it comes to information security, there's lots of laws and regulations that are being put into place to help protect the end consumer, help protect employees, and help protect the information on different people and our users. Customers are also becoming more and more demanding of companies and how companies perform and act. In fact, they're not signing contracts until they know that companies are doing the right things in protecting information security. It's also becoming more and more important for companies to have cyber security insurance, but cyber security insurance is requiring more and more to even have coverage for these companies.

Those businesses who don't have good information security practices could be at a loss, could be at a huge loss, because the impact could be devastating. The impact from cyber incidents could be loss of revenue or loss of assets. It could be judgment and fines. If there is a cyber security incident, there are mitigations and notifications that need to go out, which can be very costly. There could be a loss of competitive advantage, a loss of reputation, a loss of customers. In fact, you could actually lose a business: 60% of small businesses go out of business within 6 months after a cyber attack. So it could be real devastating.

The CIA triad

So what do we need to think about when it comes to information security? A common model out there is the CIA triad: confidentiality, integrity and availability. Confidentiality is the idea of making sure information doesn't get out, that it's not viewed by others who shouldn't have access to it. We want to keep things confidential. Integrity is the idea that our information just can't change, that no one can go in and tamper with the information. Availability is the idea that when the information is needed by those who need to have access, then that information is available to them.

Authenticity and non-repudiation

The CIA triad is a great model and it's commonly used out there and very well known. However, there are some sources out there that will actually break it into four pillars, which would include non-repudiation, and the CISSP, which is a common certification out there, a very well-known certification out there, will also add authenticity. So whether you include this as part of the CIA triad or break it apart separately, it is something to consider.

Authenticity is similar to authentication. Authenticity is the idea that when I receive information, I can guarantee that it came from a certain source. Non-repudiation is the idea that whoever sent the information can't deny that they sent that information, and the person receiving the information can't deny that they received the information.

Where cryptography fits

Cryptography has a key role in all of these. It directly correlates with how we can make things confidential, how we can have integrity, how we have authenticity and non-repudiation, and there are some indirect correlations between that and availability.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →