Jump to content

CIA triad

From Wikipedia, the free encyclopedia
The CIA triad: confidentiality, integrity, and availability.

The "CIA triad" of confidentiality, integrity, and availability sits at the heart of many information security standards.[1] The concept was introduced in the Anderson Report in 1972 and later repeated in The Protection of Information in Computer Systems. The abbreviation was coined by Steve Lipner around 1986.[2]

The triad is used in information-security standards and guidance, including the ISO/IEC 27000 family of standards and the NIST Cybersecurity Framework. ISO/IEC 27000 defines information security as the preservation of confidentiality, integrity and availability of information, while other frameworks use the three concepts as part of wider approaches to managing cyber and information-security risk.

Although the CIA triad remains influential, authors have argued that it is incomplete as a general model of information security. Alternative and expanded models have proposed additional goals such as authenticity, possession or control, utility, non-repudiation, accountability and trust. These additions are sometimes presented as separate principles, and sometimes as extensions or intersections of confidentiality, integrity and availability.

The Triad

[edit]

The triad is made up of confidentiality, integrity, and availability.

In information security, confidentiality "is the property, that information is not made available or disclosed to unauthorized individuals, entities, or processes."[3][4]Examples of confidentiality of electronic data being compromised include laptop theft, password theft, or sensitive emails being sent to the incorrect individuals.[5]

Data integrity refers to maintaining and assuring the accuracy and completeness of data over its entire lifecycle.[6] This means that data cannot be modified in an unauthorized or undetected manner.[7] Information security systems typically incorporate controls to ensure their own integrity, in particular protecting the kernel or core functions against both deliberate and accidental threats.[8] More broadly, integrity is an information security principle that involves human/social, process, and commercial integrity, as well as data integrity. As such it touches on aspects such as credibility, consistency, truthfulness, completeness, accuracy, timeliness, and assurance.[9]

For any information system to serve its purpose, the information must be available when it is needed.[10] This means the computing systems used to store and process the information, the security controls used to protect it, and the communication channels used to access it must be functioning correctly.[11] High availability systems aim to remain available at all times, preventing service disruptions due to power outages, hardware failures, and system upgrades.[12] Ensuring availability also involves preventing denial-of-service attacks, such as a flood of incoming messages to the target system, essentially forcing it to shut down.[13]

Use in standards and regulations

[edit]

Confidentiality, integrity and availability are explicitly invoked in both the ISO/IEC 27000 family of information security standards and the NIST Cybersecurity Framework.[14] ISO27000 explicitly defines Information security as the "preservation of confidentiality (3.10), integrity (3.36) and availability (3.7) of information".[4] Samonas and Cross describe it as sitting "at the heart of various security governance standards and codes of practice that have been adopted by public, private and non-governmental organizations".[1]

Additional security goals

[edit]

Between the early 1980s and the 2010s, at least eight complementary principles were proposed to be added by various authors, many of which either sat in the intersection of two of the existing triad or where in some sense a subfield of one of them.

Additional security attributes and their relationship to the CIA triad
Attribute Example formulation or application Classification by Samonas and Coss
Authenticity The Parkerian Hexad.[15] Integrity[1]
Non-repudiation Maconachy–Schou–Ragsdale model.[16] Integrity[1]
Responsibility The RITE principles for information-security management proposed by Dhillon and Backhouse.[17] Integrity[1]
Integrity of people The RITE principles.[17] Integrity[1]
Trust The RITE principles.[17] Confidentiality and integrity[1]
Ethicality The RITE principles.[17] Integrity[1]
Authentication Maconachy–Schou–Ragsdale model. Integrity.[1]


Microsoft included the security goals of Authentication, Authorization, and Nonrepudiation as part of STRIDE, such that each of the six security goals correspondent to one of the six threats in the STRIDE acronym.[18]

In 1998, Donn Parker proposed an alternative model for the classic triad that he called the six atomic elements of information. The elements are confidentiality, possession, integrity, authenticity, availability, and utility.[19] Parker is clear that the definitions of confidentially, integrity and availability he uses are different from the ones in the standard CIA triad.[20]

In 2011, The Open Group published the information security management standard O-ISM3.[21] This standard proposed an operational definition of the key concepts of security, with elements called "security objectives", related to access control, availability, data quality, compliance, and technical.

References

[edit]
  1. 1 2 3 4 5 6 7 8 9 Samonas, S.; Coss, D. (2014). "The CIA Strikes Back: Redefining Confidentiality, Integrity and Availability in Security". Journal of Information System Security. 10 (3): 5. Archived from the original on 2018-09-22. Retrieved 2018-01-25.
  2. Ham, Jeroen Van Der (2021-06-08). "Toward a Better Understanding of "Cybersecurity"". Digital Threats: Research and Practice. 2 (3): 1–3. doi:10.1145/3442445. ISSN 2692-1626.
  3. Beckers, K. (2015). Pattern and Security Requirements: Engineering-Based Establishment of Security Standards. Springer. p. 100. ISBN 978-3-319-16664-3.
  4. 1 2 ISO/IEC 27000:2020 Information technology — Security techniques — Information security management systems — Overview and vocabulary. International Organization for Standardization. 2020. ISBN 978-3-319-16664-3.
  5. Andress, J. (2014). The Basics of Information Security: Understanding the Fundamentals of InfoSec in Theory and Practice. Syngress. p. 240. ISBN 978-0-12-800812-6.
  6. Boritz, J. Efrim (2005). "IS Practitioners' Views on Core Concepts of Information Integrity". International Journal of Accounting Information Systems. 6 (4). Elsevier: 260–279. doi:10.1016/j.accinf.2005.07.001.
  7. Hryshko, I. (2020). "Unauthorized Occupation of Land and Unauthorized Construction: Concepts and Types of Tactical Means of Investigation". International Humanitarian University Herald. Jurisprudence (43): 180–184. doi:10.32841/2307-1745.2020.43.40. ISSN 2307-1745.
  8. Pevnev, V. (2018). "Model Threats and Ensure the Integrity of Information". Systems and Technologies. 2 (56): 80–95. doi:10.32836/2521-6643-2018.2-56.6. ISSN 2521-6643.
  9. "Completeness, Consistency, and Integrity of the Data Model". Measuring Data Quality for Ongoing Improvement. MK Series on Business Intelligence. Elsevier. 2013. pp. e11–e19. doi:10.1016/b978-0-12-397033-6.00030-4. ISBN 978-0-12-397033-6. Retrieved 2021-05-29.
  10. Video from SPIE - the International Society for Optics and Photonics. doi:10.1117/12.2266326.5459349132001.
  11. "Communication Skills Used by Information Systems Graduates". Issues in Information Systems. 2005. doi:10.48009/1_iis_2005_311-317. ISSN 1529-7314.
  12. Outages of electric power supply resulting from cable failures Boston Edison Company system (Report). 1980-07-01. doi:10.2172/5083196. OSTI 5083196. Archived from the original on 2022-01-19. Retrieved 18 January 2022.
  13. Loukas, G.; Oke, G. (September 2010) [August 2009]. "Protection Against Denial of Service Attacks: A Survey" (PDF). Comput. J. 53 (7): 1020–1037. doi:10.1093/comjnl/bxp078. Archived from the original (PDF) on 2012-03-24. Retrieved 2015-08-28.
  14. "The NIST Cybersecurity Framework (CSF) 2.0" (PDF). 26 February 2024. Archived (PDF) from the original on 18 June 2026. Retrieved 4 July 2026.
  15. Parker, Donn B. (1998). Fighting Computer Crime: A New Framework for Protecting Information. John Wiley & Sons. ISBN 978-0-471-16378-7.
  16. Maconachy, W.; Schou, Corey; Welch, Don (2001-01-01). "A Model for Information Assurance:An Integrated Approach". Proceedings of the 2001 IEEE Workshop on Information Assurance and Security.
  17. 1 2 3 4 Dhillon, Gurpreet; Backhouse, James (2000). "Information System Security Management in the New Millennium". Communications of the ACM. 43 (7): 125–128. doi:10.1145/341852.341877.
  18. kexugit. "Uncover Security Design Flaws Using The STRIDE Approach". learn.microsoft.com. Retrieved 2026-07-03.
  19. Parker, Donn B. (1998). Fighting computer crime: a new framework for protecting information. New York Chichester Weinheim: J. Wiley & sons. p. 15. ISBN 978-0-471-16378-7.
  20. Parker, Donn (July 2010). "Our excessively simplistic information security model and how to fix it" (PDF). The ISSA Journal. p. 16. Archived from the original on 31 Dec 2010. Retrieved 2025-02-04.
  21. Aceituno, Vicente. "Open Information Security Maturity Model". Archived from the original on 16 February 2017. Retrieved 12 February 2017.