The idea
The CIA Triad gives a useful starting point for asking what needs protecting.
- Confidentiality: information is accessible only to authorised people and systems.
- Integrity: information remains accurate and is protected against improper changes.
- Availability: authorised users can access information and services when needed.
Putting it into context
A fictional online booking service needs to keep customer details private, preserve accurate appointments and remain available when customers need it. Protecting one objective alone would not make the service secure.
Controls to consider
Access controls and encryption can support confidentiality. Change controls and integrity checks can help protect integrity. Backups, resilience and tested recovery can support availability. A control may serve more than one objective.
Further reading
NIST glossary: confidentiality, integrity and availability.