TechKnowSurge
NIST NICE K0728 CompTIA Tech+ 6.1 ISC2 CC 1.1 Cisco CCST Cybersecurity 1.1 NIST NICE K0682 Cisco CCST Cybersecurity 1.2 ISC2 CC 1.2 CompTIA Network+ 4.2
VideoSecurityFree

Cybersecurity - The CIA Triad

The CIA Triad is a foundational cybersecurity model built on three principles: confidentiality, integrity, and availability. It provides a framework for evaluating and protecting any technology, system, or service an organization operates.

Complete this video to capture a CTF flag worth 1 point.

About this video

The CIA Triad is a foundational cybersecurity model used to evaluate the security posture of any technology, system, or service an organization operates. Defined by CISA as the practice of ensuring confidentiality, integrity, and availability of information, the triad gives security professionals a structured way to think through how a given technology should be protected and what risks it faces. Each of the three components addresses a distinct dimension of security that must be considered independently and together. Confidentiality focuses on restricting access to information so that only authorized individuals can view or use it. Integrity ensures that data and systems remain accurate and complete, unaltered by unauthorized parties or processes. Certificates and validation mechanisms are common tools used to enforce integrity. Availability ensures that systems, data, and services are accessible to authorized users whenever they are needed, making uptime and resilience critical concerns. Threats to the CIA Triad extend well beyond external cyberattacks. A hacker breaching a website may steal data, tamper with content, or launch a denial-of-service attack, targeting confidentiality, integrity, and availability respectively. However, internal risks are equally significant. Misconfigured systems by administrators, accidental execution of destructive database commands, electrical failures, natural disasters, and poorly structured incident response plans can each compromise one or more pillars of the triad. Even organizational decisions such as hiring underqualified or unvetted personnel represent real threats to overall security. The CIA Triad serves as a practical, ongoing reference point for measuring risk and building defenses across an organization's entire technology environment.

What you'll learn

What's covered

CIA Triad

Aligned to

NIST NICE
K0728 Knowledge of Confidentiality, Integrity and Availability (CIA) principles and practices
K0682 Knowledge of cybersecurity threats
CompTIA Tech+
6.1 Summarize confidentiality, integrity, and availability concerns
ISC2 CC
1.1 Understand cybersecurity concepts
1.2 Understand risk management concepts
Cisco CCST Cybersecurity
1.1 Define essential security principles
1.2 Explain common threats and vulnerabilities
CompTIA Network+
4.2 Summarize various types of attacks and their impact to the network

Key terms

CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Denial of Service
DoS
An attack that floods a system or network with traffic to make it unavailable to legitimate users.
Incident Response
IR
A structured process for identifying, containing, eradicating, and recovering from security incidents.
Misconfiguration
An incorrect or insecure system or service setting made by an administrator that can expose vulnerabilities affecting confidentiality, integrity, or availability.

Topics

Cia Triad Cybersecurity Information Security Confidentiality Integrity Availability

Transcript

The CIA Triad

The CIA Triad is a model that we use in the cyber security realm to make sure that we're thinking of all the different aspects when it comes to cyber security. It really boils down to three main things that we're looking for: keeping safe, making sure that our network is functioning well, and protecting our businesses and organizations.

In the definition of cyber security as defined by cisa.gov, there are three components to cyber security: it's the practice of ensuring confidentiality, integrity and availability of information. So there you have it — there is the CIA: confidentiality, integrity and availability.

The CIA Triad is a model that we use in cyber security to make sure that we're thinking about all of the aspects of any particular technology. When I say technology, that could be information, it could be data, it could be a website, it could be some sort of service that we're operating. It makes sure that we're thinking about confidentiality, about integrity, and about availability. So we measure this model against our different technologies to think about how we are going to protect those different technologies.

Confidentiality

Confidentiality just says that we are protecting that technology from being accessed or being seen by somebody that shouldn't see it — that only those who are supposed to see that information, see that website, see whatever service it is, are able to see it, but no one else is able to see it.

Integrity

The idea of integrity is that as you are seeing the information, the website, whatever the technology is, it is accurate and it is complete, and that nothing has gotten in the way to give you wrong information. That is the integrity of the information. One of the things that we use to enforce integrity is certificates. We'll talk more about that, but integrity is the idea that the information is accurate and complete.

Availability

Then we have availability. That's the idea that that information is accessible when we need it to be accessible — still with the idea that it's the proper person that's seeing it, it's the right information, and that they can see it, that it is available.

Threats to the Triad

If we take a look at some threats to the CIA Triad, it might give us some better perspective on what this actually looks like.

Let's say we have a hacker and they hack into your company's website and they start seeing information that they shouldn't see, and they're stealing that information. Perhaps it's some sort of company secrets, or maybe it's customer data. Well, that's confidentiality right there; that's a breach of confidentiality, that information got out that shouldn't have got out.

Or maybe that hacker goes in and starts changing the data — that's integrity right there. Maybe they go in there and change the website so now it's showing inappropriate information, damaging the company's reputation. So that is integrity right there.

And then you have availability. Maybe they launch a denial of service attack, or bring the website down so that other customers can't access that website. Now you have an availability issue.

Hackers Are Not the Only Threat

But hackers are not the only threat to the CIA Triad. In fact, from my experience, cyber crime is not the biggest thing that I'm concerned about when it comes to the CIA Triad.

When I have system administrators or network engineers, they can make incorrect configuration changes on equipment or on services that expose things — so a lack of confidentiality, because they've exposed something because of a configuration change. Or perhaps they executed a SQL command that changed data and now the data is wrong. Or perhaps they made a configuration change that has brought the system down and it's affected availability.

But that's not the only thing either. It could be something like electrical issues or fires or earthquakes that can bring our network down, or bring the information down, or bring our services down.

Another thing is a bad incident response plan. A bad incident response plan is not going to bring our network down, it's not going to limit our availability there, but what can happen is that if the network does go down and we are not organized in the approach that we take to fix the network, then our availability could be down longer than it needs to be. A good incident response plan will limit how long our downtime is, whereas a bad one could extend that downtime and affect our availability over the life of our services, or whatever services that we're offering. So you can see that even a bad incident response plan is an example of a threat to the CIA Triad.

Or another thing is even our hiring practices — hiring technicians that are not experienced, or hiring people who are going to hack our network. So even things that fall outside of what you typically think of as far as technology is concerned could affect our CIA Triad here.

So the CIA Triad is a great model that we can use to measure up each one of our technologies and guard against these threats. It's a model that you actually keep in mind as we move forward, and we're going to use that model through the rest of this course.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →