CIA Triad

on

BLUF
The CIA triad is a model to help set guidelines for organizations when it comes to information security. The CIA triad is the most crucial and foundational element for cybersecurity needs. Authentication verifies who a user is while authorization is the permissions a user has on a a system or network.


CIA Triad


The CIA triad is made up of three elements: confidentiality, integrity, and availability. Organizations use the CIA triad to set up the guidelines for how they will run their information security. The concept of the CIA triad was not created by one person, but over time people came to see the three concepts come together.

Confidentiality

Confidentiality refers to the security of sensitive information within an organization. This could include bank statements, passwords, usernames, PII, and more. Confidentiality of a company can be protected by separating the data from unauthorized users. There are several methods an organization can use to protect their data as well as training and educating users that have access to protected information. (Unitrends, 2021)

Integrity

The integrity portion of the triad concerns the authenticity, reliability, and whether the data is correct. It is important the data isn’t corrupted during transit or changed to be untrue. Organizations must set up measures to protect data from unauthorized users and set up counter measures to recover deleted or damaged data. (Wesley Chai, 2022)

Availability

This principle refers to data, systems, applications being available to authorized users whenever it is needed. A lack of availability can lead to many problems within an organization. Availability can be maintained by redundancy, backups, patching and system upgrades, and disaster recovery. (Unitrends, 2021)

Authentication vs Authorization


Authentication
Authentication is the process of verifying a user is who they say they are. This can be verified by passwords, biometrics, pin codes, or phrases. Precautions like these help ensure data is protected. For example, authentication can be compared to a bouncer outside of a bar. They check your ID, reference the picture with how you look and may even ask you questions to verify the information. (Xplodivity, 2024)

Authorization
Authorization is the process of setting permissions and access for a user after they have been authenticated. This separates users from data they are not permitted to see or opens up access to data they are privileged to see. To build on the previous example of a bar, authorization can be compared to a stamp that authorizes you to different spaces within the bar. People with a stamp may have access to the VIP section while people without a stamp are constrained to the dance floor and bar. Authorization keeps users away from sensitive data they don’t need to see.
(Xplodivity, 2024)

Conclusion
The CIA triad is an important concept that sets the foundation for information security. The triad has helped prevent and recover from cyber attacks since the 1970s, and will continue to do so in the future. Organizations can use the triad to protect data from cyber attacks or failures, whether it is human error, nature, and unforeseen events.

References
Wesley Chai (2022) What is the CIA Triad? Definition,Explanation, Examples
https://drive.google.com/file/d/1898r4pGpKHN6bmKcwlxPdVZpCC6Moy8l/view?pli=1

Unitrends (2021) The CIA Triad and Its Importance in Data Security
https://www.unitrends.com/blog/cia-triad-confidentiality-integrity-availability/

Xplodivity (2024) Authentication vs Authorization Explained
https://www.youtube.com/watch?v=7ijBiXddB7w

Leave a Reply

Your email address will not be published. Required fields are marked *