The CIA triad—confidentiality, integrity, and availability—defines the core objectives of cybersecurity, and the five pillars model extends this framework by adding authenticity and non-repudiation. Together, these models provide a structured way to evaluate and measure the security of any system or design.
CIA Triad & Five Pillars
There are many different models that help us take a look at our security programs and evaluate them to see if they're correct, to see if they are comprehensive enough. One of those security models is the CIA triad. The CIA triad is a very popular, very well-known way of looking at cyber security and what it covers.
One of the agencies that gives us a ton of resources around cyber security is CISA. CISA stands for the Cybersecurity and Infrastructure Security Agency. It's run by the US government, so the US government puts out a ton of resources, and one of the things that they do is define cyber security. Cyber security is the art of protecting networks, devices and data from unauthorized access or criminal use, and the practice of ensuring confidentiality, integrity and availability. Notice confidentiality, the C; integrity, the I; and availability, the A. Well, that's where we get the CIA triad from.
The CIA triad is really what we're trying to accomplish when it comes to cyber security. That is, we're trying to accomplish a certain level of confidentiality, a certain level of integrity, and a certain level of availability, and by accomplishing this we are making things more secure.
Let's just do a quick rundown of the CIA triad. Confidentiality just means that things are not viewed by people who shouldn't view them. Here we've got a set of glasses to represent that no one's going to see something that they shouldn't see, that we don't want them to see. Then we've got integrity, and that just means that something hasn't changed: that when somebody's sending me a message, there aren't components within that message that are changed by the time I get it. So it's making sure that there's a certain level of accuracy with what is given to me. And availability just means that I can get to the resources that I need to get to.
The CIA triad really covers most of what you need when it comes to security, and it's really thought of as kind of the gold standard, or the primary model, when it comes to what security is. But there are some sources that expand on this idea. For instance, the CISSP uses the five pillars of cyber security. So that's confidentiality, integrity and availability, and they add authenticity and non-repudiation.
Authenticity means that if I receive a message, I can authenticate the message, or that there's a certain level of authenticity to that message so that I know who it came from. And non-repudiation is kind of a similar idea: whoever sent the message can't refute it and say they didn't send that message. So there are similar concepts there. You could kind of maybe roll it into integrity or one of these other categories, but the CISSP breaks them out into their own pillars. And so now we've got five pillars here: confidentiality, integrity, availability, authenticity, and non-repudiation.
So how does this play into our design requirements? We take a look at our design requirements and we can say: does our design have the level of confidentiality that we need? Does it have the level of integrity that we need, the level of availability, authenticity, and non-repudiation that we need? And so now we start creating this measuring stick to understand what it is that we're looking at in these systems, rather than just saying "is it secure?" What are we looking at, what level of security? It's too big. So we break it down into confidentiality, integrity, availability, authenticity, and non-repudiation, to really understand what elements we're looking at when it comes to security of the systems we're designing.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →