TechKnowSurge
VideoSecurityFree

CIA Triad and the 5-Pillars of Security

The CIA triad—confidentiality, integrity, and availability—defines the core objectives of cybersecurity, and the five pillars model extends this framework by adding authenticity and non-repudiation. Together, these models provide a structured way to evaluate and measure the security of any system or design.

Complete this video to capture a CTF flag worth 1 point.

About this video

The CIA triad is a foundational cybersecurity framework that breaks security down into three measurable objectives: confidentiality, integrity, and availability. Confidentiality ensures that sensitive data is not accessed by unauthorized individuals. Integrity ensures that data remains accurate and unmodified between its source and its destination. Availability ensures that authorized users can reliably access the systems and resources they need. CISA, the U.S. Cybersecurity and Infrastructure Security Agency, formally defines cybersecurity in terms of these three principles, cementing the CIA triad as the primary model for understanding what security is meant to accomplish. While the CIA triad covers the majority of security concerns, the five pillars of cybersecurity—used within the CISSP framework—extends the model by incorporating two additional principles: authenticity and non-repudiation. Authenticity refers to the ability to verify that a message, transaction, or identity is genuinely what it claims to be. Non-repudiation ensures that the originator of a message or action cannot later deny having sent or performed it. Although these concepts share some overlap with integrity, treating them as distinct pillars provides a more precise vocabulary for identifying and addressing specific security requirements. Applied together, the CIA triad and the five pillars give security professionals and system designers a structured measuring stick for evaluating any network, device, or data environment. Rather than asking broadly whether a system is secure, these frameworks make it possible to ask targeted questions: Does this design provide sufficient confidentiality? Is integrity maintained across data transfers? Are availability requirements met? Can communications be authenticated and traced? This level of specificity is what transforms security from an abstract goal into a set of concrete, assessable design requirements.

What you'll learn

What's covered

CIA Triad & Five Pillars

Key terms

CIA Triad
The three core principles of information security: Confidentiality, Integrity, and Availability.
Confidentiality
The principle that information is accessible only to those authorized to access it.
Integrity
The assurance that data has not been tampered with and remains accurate and complete.
Availability
The assurance that systems and data are accessible and operational when needed by authorized users.
Authenticity
The assurance that information or a communication originates from the claimed source and has not been fabricated or impersonated. Digital signatures and certificates are common mechanisms for establishing authenticity.
Non-repudiation
The assurance that a party cannot deny having sent or received a message or performed an action.

Topics

Cia Triad Five Pillars Of Security Confidentiality Integrity Availability Non Repudiation Authenticity Information Security

Transcript

The CIA triad

There are many different models that help us take a look at our security programs and evaluate them to see if they're correct, to see if they are comprehensive enough. One of those security models is the CIA triad. The CIA triad is a very popular, very well-known way of looking at cyber security and what it covers.

One of the agencies that gives us a ton of resources around cyber security is CISA. CISA stands for the Cybersecurity and Infrastructure Security Agency. It's run by the US government, so the US government puts out a ton of resources, and one of the things that they do is define cyber security. Cyber security is the art of protecting networks, devices and data from unauthorized access or criminal use, and the practice of ensuring confidentiality, integrity and availability. Notice confidentiality, the C; integrity, the I; and availability, the A. Well, that's where we get the CIA triad from.

The CIA triad is really what we're trying to accomplish when it comes to cyber security. That is, we're trying to accomplish a certain level of confidentiality, a certain level of integrity, and a certain level of availability, and by accomplishing this we are making things more secure.

Let's just do a quick rundown of the CIA triad. Confidentiality just means that things are not viewed by people who shouldn't view them. Here we've got a set of glasses to represent that no one's going to see something that they shouldn't see, that we don't want them to see. Then we've got integrity, and that just means that something hasn't changed: that when somebody's sending me a message, there aren't components within that message that are changed by the time I get it. So it's making sure that there's a certain level of accuracy with what is given to me. And availability just means that I can get to the resources that I need to get to.

The five pillars of cyber security

The CIA triad really covers most of what you need when it comes to security, and it's really thought of as kind of the gold standard, or the primary model, when it comes to what security is. But there are some sources that expand on this idea. For instance, the CISSP uses the five pillars of cyber security. So that's confidentiality, integrity and availability, and they add authenticity and non-repudiation.

Authenticity means that if I receive a message, I can authenticate the message, or that there's a certain level of authenticity to that message so that I know who it came from. And non-repudiation is kind of a similar idea: whoever sent the message can't refute it and say they didn't send that message. So there are similar concepts there. You could kind of maybe roll it into integrity or one of these other categories, but the CISSP breaks them out into their own pillars. And so now we've got five pillars here: confidentiality, integrity, availability, authenticity, and non-repudiation.

How this plays into design requirements

So how does this play into our design requirements? We take a look at our design requirements and we can say: does our design have the level of confidentiality that we need? Does it have the level of integrity that we need, the level of availability, authenticity, and non-repudiation that we need? And so now we start creating this measuring stick to understand what it is that we're looking at in these systems, rather than just saying "is it secure?" What are we looking at, what level of security? It's too big. So we break it down into confidentiality, integrity, availability, authenticity, and non-repudiation, to really understand what elements we're looking at when it comes to security of the systems we're designing.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →