The CIA Triad is a foundational cybersecurity model built on three principles: confidentiality, integrity, and availability. It provides a framework for evaluating and protecting any technology, system, or service an organization operates.
CIA Triad
The CIA Triad is a model that we use in the cyber security realm to make sure that we're thinking of all the different aspects when it comes to cyber security. It really boils down to three main things that we're looking for: keeping safe, making sure that our network is functioning well, and protecting our businesses and organizations.
In the definition of cyber security as defined by cisa.gov, there are three components to cyber security: it's the practice of ensuring confidentiality, integrity and availability of information. So there you have it — there is the CIA: confidentiality, integrity and availability.
The CIA Triad is a model that we use in cyber security to make sure that we're thinking about all of the aspects of any particular technology. When I say technology, that could be information, it could be data, it could be a website, it could be some sort of service that we're operating. It makes sure that we're thinking about confidentiality, about integrity, and about availability. So we measure this model against our different technologies to think about how we are going to protect those different technologies.
Confidentiality just says that we are protecting that technology from being accessed or being seen by somebody that shouldn't see it — that only those who are supposed to see that information, see that website, see whatever service it is, are able to see it, but no one else is able to see it.
The idea of integrity is that as you are seeing the information, the website, whatever the technology is, it is accurate and it is complete, and that nothing has gotten in the way to give you wrong information. That is the integrity of the information. One of the things that we use to enforce integrity is certificates. We'll talk more about that, but integrity is the idea that the information is accurate and complete.
Then we have availability. That's the idea that that information is accessible when we need it to be accessible — still with the idea that it's the proper person that's seeing it, it's the right information, and that they can see it, that it is available.
If we take a look at some threats to the CIA Triad, it might give us some better perspective on what this actually looks like.
Let's say we have a hacker and they hack into your company's website and they start seeing information that they shouldn't see, and they're stealing that information. Perhaps it's some sort of company secrets, or maybe it's customer data. Well, that's confidentiality right there; that's a breach of confidentiality, that information got out that shouldn't have got out.
Or maybe that hacker goes in and starts changing the data — that's integrity right there. Maybe they go in there and change the website so now it's showing inappropriate information, damaging the company's reputation. So that is integrity right there.
And then you have availability. Maybe they launch a denial of service attack, or bring the website down so that other customers can't access that website. Now you have an availability issue.
But hackers are not the only threat to the CIA Triad. In fact, from my experience, cyber crime is not the biggest thing that I'm concerned about when it comes to the CIA Triad.
When I have system administrators or network engineers, they can make incorrect configuration changes on equipment or on services that expose things — so a lack of confidentiality, because they've exposed something because of a configuration change. Or perhaps they executed a SQL command that changed data and now the data is wrong. Or perhaps they made a configuration change that has brought the system down and it's affected availability.
But that's not the only thing either. It could be something like electrical issues or fires or earthquakes that can bring our network down, or bring the information down, or bring our services down.
Another thing is a bad incident response plan. A bad incident response plan is not going to bring our network down, it's not going to limit our availability there, but what can happen is that if the network does go down and we are not organized in the approach that we take to fix the network, then our availability could be down longer than it needs to be. A good incident response plan will limit how long our downtime is, whereas a bad one could extend that downtime and affect our availability over the life of our services, or whatever services that we're offering. So you can see that even a bad incident response plan is an example of a threat to the CIA Triad.
Or another thing is even our hiring practices — hiring technicians that are not experienced, or hiring people who are going to hack our network. So even things that fall outside of what you typically think of as far as technology is concerned could affect our CIA Triad here.
So the CIA Triad is a great model that we can use to measure up each one of our technologies and guard against these threats. It's a model that you actually keep in mind as we move forward, and we're going to use that model through the rest of this course.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →