← Core Concepts

Core Concepts

CIA Triad

Confidentiality, integrity and availability: three objectives for protecting information.

Foundations

The idea

The CIA Triad gives a useful starting point for asking what needs protecting.

  • Confidentiality: information is accessible only to authorised people and systems.
  • Integrity: information remains accurate and is protected against improper changes.
  • Availability: authorised users can access information and services when needed.

Putting it into context

A fictional online booking service needs to keep customer details private, preserve accurate appointments and remain available when customers need it. Protecting one objective alone would not make the service secure.

Controls to consider

Access controls and encryption can support confidentiality. Change controls and integrity checks can help protect integrity. Backups, resilience and tested recovery can support availability. A control may serve more than one objective.

Further reading

NIST glossary: confidentiality, integrity and availability.