Blog Layout

The Cybersecurity Lair • August 23, 2023

101 Series | Security and Risk Management | CIA

Introduction to the Confidentiality Integrity and Availability concepts

No, not that agency you might have in mind, and no, not as complicate as shown in the image above. But now that we have your attention, let's get into some of the most basic concepts of Cybersecurity and/or Information Security fundamental goals: Confidentiality, Integrity and Availability. It really does not matter the order of the acronym. And don´t forget to add the word triad at the end.


This is kind of a big deal. Yes it is. Could be simple at sight, but if we do not understand the very basic needs for cybersecurity, we will for sure get trouble to further develop solutions to cover these essentials.


Let's first go directly to why. Nowadays the success of business relies mainly on technology. Especially Information Technology. We cannot imagine a company running their business the old fashion way. Main business processes and core components of the nowadays enterprise are digital based. 


Ergo, in order to run a company smoothly in the Digital Era, we need to protect our assets against unauthorised access or modification to them and keep them available for business users to perform their daily tasks to achieve their business goals. And one of the most valuable assets an enterprise has is its data, their information.


Now into our business.


Confidentiality means to maintain the necessary level of sensitivity to protect the information of unauthorised disclosure events, meaning keep unauthorised people away from sensitive data.


When we are talking about integrity, we are dealing with the accuracy and reliability of information and data within systems, and the capacity of that system to prevent unauthorised modifications (delete, change or add data).


Lastly: availability. Is to make access reliable to information or specific resources to authorised business users.


Simple right?





Harris, Shon & Maymí, Fernando. CISSP EXAM GUIDE Seventh Edition. New York McGraw Hill Education, 2016.


Executive Summary — NIST SP 1800-26  documentation. (n.d.). https://www.nccoe.nist.gov/publication/1800-26/VolA/index.html#:~:text=The%20CIA%20triad%20represents%20the,personal%20privacy%20and%20proprietary%20information

Share by: