TechKnowSurge
NIST NICE K1120 CompTIA Tech+ 6.1 NIST NICE K0686 CompTIA Tech+ 6.4 Cisco CCST Cybersecurity 1.3 NIST 800-53 SC-23
VideoSecurityFree

Cybersecurity - The 5 Pillars of Cybersecurity

The five pillars of cybersecurity expands on the CIA triad by adding authenticity and non-repudiation, providing a more complete framework for evaluating an organization's security posture.

Complete this video to capture a CTF flag worth 1 point.

About this video

The CIA triad — confidentiality, integrity, and availability — has long served as a foundational framework for evaluating how well an organization protects its assets. Confidentiality ensures that data is accessible only to authorized parties, integrity ensures that data remains unaltered, and availability ensures that data and systems are accessible when needed. While this model remains widely used, it does not fully address every dimension of modern cybersecurity risk. The five pillars of cybersecurity extends the CIA triad by adding authenticity and non-repudiation. Authenticity refers to the assurance that a message or communication genuinely originated from the claimed source — for example, verifying that an email received from a colleague was not spoofed or forged. This concept is related to but distinct from authentication, which involves proving one's identity to gain access to a system through mechanisms such as passwords or multi-factor verification. Authenticity concerns the origin of a communication, while authentication concerns the identity of a user attempting to access a resource. Non-repudiation complements authenticity by ensuring that once a message has been sent or received, neither party can credibly deny their involvement. This is particularly important in legal, financial, and compliance scenarios where a verifiable record of communication is required. Together, these five pillars — confidentiality, integrity, availability, authenticity, and non-repudiation — form a comprehensive model adopted by leading industry bodies, including ISC2, the organization responsible for the globally recognized CISSP certification.

What you'll learn

What's covered

Five Pillars of Cybersecurity

Aligned to

NIST NICE
K1120 Knowledge of Confidentiality, Integrity, Availability, Authenticity, and Non-repudiation (CIAAN) principles and practices
K1120 Knowledge of Confidentiality, Integrity, Availability, Authenticity, and Non-repudiation (CIAAN) principles and practices
K1120 Knowledge of Confidentiality, Integrity, Availability, Authenticity, and Non-repudiation (CIAAN) principles and practices
K0686 Knowledge of authentication and authorization tools and techniques
CompTIA Tech+
6.1 Summarize confidentiality, integrity, and availability concerns.
6.4 Compare and contrast authentication, authorization, accounting, and non-repudiation concepts.
Cisco CCST Cybersecurity
1.3 Explain access management principles
NIST 800-53
SC-23 Session Authenticity

Key terms

CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Non-repudiation
The assurance that a party cannot deny having sent or received a message or performed an action.
Authentication
The process of verifying the identity of a user, device, or system.
Authenticity
The assurance that information or a communication originates from the claimed source and has not been fabricated or impersonated. Digital signatures and certificates are common mechanisms for establishing authenticity.

Topics

Cybersecurity Cia Triad Five Pillars Of Cybersecurity Non Repudiation Authenticity Security Frameworks

Transcript

The CIA triad is one of the most well-known models when it comes to cybersecurity. It's a way that we can look at cybersecurity, a way that we can look at our assets, a way we can look at our organization and ask ourselves, are we secure? What do we need to think about when it comes to securing our organization? But it's not the only model that's out there. Another popular model that you can find out there is the five pillars of cybersecurity, which incorporates the CIA triad.

The CIA triad is a big part of cybersecurity. That is when we take a look at an asset, for instance data, we take a look at it and say: are we remaining confidential with that data, are we making sure that it's not released to those who are not supposed to view that data? Do we have a certain level of integrity to that data, that that data is not changing or being altered? And how is that data being available when it's needed, is it accessible? So the CIA triad is a way that we can measure up to be able to understand, are we protecting our assets?

But it's not the only model. The five pillars is a similar concept that we can measure up our organization to make sure that we are remaining secure, and it includes the CIA triad. It includes confidentiality, integrity, and availability. But what it adds is two other components to it. It adds authenticity and non-repudiation.

Authenticity

Authenticity is the idea that when we receive something, there's a certain level of guarantee that it came from a specific source. So in this example right here, let's say Susan receives some information from David in the form of maybe an email. How do we know that this email actually came from David? And the thing is, with email systems it could really come from anyone. So how do we prove that this actually has come from David? This is the idea of authenticity. What is the authenticity of this email that's being sent to Susan? And there's some mechanisms that we can put in place to prove that authenticity, to prove that it came from David. So authenticity is this idea that when you receive something, it's authentic.

Authenticity is sometimes confused with authentication. These are two different concepts. Although there is a little bit of overlap, they are two different things. And so what is the difference here? Authentication would be me logging into a system, proving who I am by maybe some sort of ID. Maybe we're using some sort of text message or email to verify. Maybe it's a two-factor authentication, maybe password. There are different ways that I authenticate with a system to log in. Authenticity is proving that a message is coming from a certain person, or communication is coming from a certain person. So one might argue that authenticity is a component of authentication, but they are two different concepts. One is the authenticity of the message or the communication, versus the other one is whether I have properly identified who I am and am able to log into a system.

Non-repudiation

The other concept here is non-repudiation. Non-repudiation is this idea that when a message gets sent, people cannot deny that they either sent this message or received this message. They can't repudiate or challenge that, hey, I didn't send that. Hey, I didn't receive that. So there are systems that we can put in place that prove that this message was sent from David. That's the authenticity piece. And David can't then deny, hey, I didn't send that message. And Susan can't deny, hey, I didn't receive that message. And this is important for things like legal messages that are being sent back and forth. So there needs to be some sort of proof that this communication happened.

We see the five pillars of cybersecurity being used by organizations such as ISC2, who is the one that puts out the CISSP certification, one of the most popular certifications within cybersecurity.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →