The five pillars of cybersecurity expands on the CIA triad by adding authenticity and non-repudiation, providing a more complete framework for evaluating an organization's security posture.
Five Pillars of Cybersecurity
The CIA triad is one of the most well-known models when it comes to cybersecurity. It's a way that we can look at cybersecurity, a way that we can look at our assets, a way we can look at our organization and ask ourselves, are we secure? What do we need to think about when it comes to securing our organization? But it's not the only model that's out there. Another popular model that you can find out there is the five pillars of cybersecurity, which incorporates the CIA triad.
The CIA triad is a big part of cybersecurity. That is when we take a look at an asset, for instance data, we take a look at it and say: are we remaining confidential with that data, are we making sure that it's not released to those who are not supposed to view that data? Do we have a certain level of integrity to that data, that that data is not changing or being altered? And how is that data being available when it's needed, is it accessible? So the CIA triad is a way that we can measure up to be able to understand, are we protecting our assets?
But it's not the only model. The five pillars is a similar concept that we can measure up our organization to make sure that we are remaining secure, and it includes the CIA triad. It includes confidentiality, integrity, and availability. But what it adds is two other components to it. It adds authenticity and non-repudiation.
Authenticity is the idea that when we receive something, there's a certain level of guarantee that it came from a specific source. So in this example right here, let's say Susan receives some information from David in the form of maybe an email. How do we know that this email actually came from David? And the thing is, with email systems it could really come from anyone. So how do we prove that this actually has come from David? This is the idea of authenticity. What is the authenticity of this email that's being sent to Susan? And there's some mechanisms that we can put in place to prove that authenticity, to prove that it came from David. So authenticity is this idea that when you receive something, it's authentic.
Authenticity is sometimes confused with authentication. These are two different concepts. Although there is a little bit of overlap, they are two different things. And so what is the difference here? Authentication would be me logging into a system, proving who I am by maybe some sort of ID. Maybe we're using some sort of text message or email to verify. Maybe it's a two-factor authentication, maybe password. There are different ways that I authenticate with a system to log in. Authenticity is proving that a message is coming from a certain person, or communication is coming from a certain person. So one might argue that authenticity is a component of authentication, but they are two different concepts. One is the authenticity of the message or the communication, versus the other one is whether I have properly identified who I am and am able to log into a system.
The other concept here is non-repudiation. Non-repudiation is this idea that when a message gets sent, people cannot deny that they either sent this message or received this message. They can't repudiate or challenge that, hey, I didn't send that. Hey, I didn't receive that. So there are systems that we can put in place that prove that this message was sent from David. That's the authenticity piece. And David can't then deny, hey, I didn't send that message. And Susan can't deny, hey, I didn't receive that message. And this is important for things like legal messages that are being sent back and forth. So there needs to be some sort of proof that this communication happened.
We see the five pillars of cybersecurity being used by organizations such as ISC2, who is the one that puts out the CISSP certification, one of the most popular certifications within cybersecurity.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →