When I first learned about the CIA Triad, it seemed like a pretty simple concept, but the more I looked into it, the more I realized how much of cybersecurity connects back to these three principles. The CIA Triad stands for confidentiality, integrity, and availability. According to Chai (2022), these three ideas are used as a model to help guide information security policies within an organization. Even though each part focuses on something different, they all have to work together. An organization could have great confidentiality, for example, but it would still have a serious problem if its systems were constantly unavailable or the information in them could not be trusted.
Confidentiality, Integrity, and Availability
Confidentiality is basically making sure information is only seen by people who are supposed to have access to it. The easiest way for me to relate to this is the military idea of “need to know.” Just because someone has access to a network or works in the same organization does not mean they should automatically have access to every file. Chai (2022) explains that confidentiality measures are meant to prevent unauthorized access to sensitive information. Some examples are passwords, encryption, two-factor authentication, security tokens, and access controls. This is important because organizations hold a lot of information that could cause damage if it got into the wrong hands, such as personal information, financial records, business plans, or military information.
Integrity is about being able to trust the information you’re looking at. Information should stay accurate and should not be changed or deleted by someone who is not authorized to do so. Chai (2022) describes integrity as maintaining the consistency, accuracy, and trustworthiness of data throughout its lifecycle. This can be protected with things like file permissions, access controls, backups, version control, checksums, and digital signatures. To me, integrity is just as important as confidentiality because having information available does not do much good if nobody can be sure it is correct. In a military setting, for example, altered intelligence or incorrect information could lead to people making decisions based on something that is not true.
Availability means that the people who are authorized to use a system or information can actually get to it when they need it. Chai (2022) explains that this includes maintaining the hardware and infrastructure that holds and displays information. Backups, redundancy, system updates, failover systems, network monitoring, and disaster recovery plans can all help with availability. This is especially important for places like hospitals, banks, emergency services, and the military. If an important system goes down at the wrong time, the problem can become much bigger than just an inconvenience.
Authentication and Authorization
Authentication and authorization sound similar, and I used to think they were basically the same thing, but they actually answer two different questions. Authentication is proving that you are really the person you claim to be. A good example from the military is using a Common Access Card (CAC) and PIN to log into a computer. The credentials are used to verify the user’s identity. Authorization comes after that and determines what that person is actually allowed to access or do. For example, two service members could both successfully log in with their CACs, but that does not mean they should both have access to the same files, programs, or classified information. One person may be authorized for something that the other person is not. This is why both authentication and authorization are important. A system needs to know who you are, but it also needs to limit what you can do after you log in.
Real-World Cybersecurity Incident
One real-world example that shows why the CIA Triad matters is the 2024 Change Healthcare cyberattack. The ransomware attack affected a major part of the U.S. healthcare system and involved both stolen information and interruptions to services. The U.S. Department of Health and Human Services reported that Change Healthcare later identified approximately 192.7 million individuals as being impacted by the incident (U.S. Department of Health and Human Services, 2025).
I think this incident is a good example because it shows that one cyberattack can affect more than one part of the CIA Triad. Confidentiality was affected because protected health information was compromised. Availability was also affected because healthcare services and systems were disrupted. The effects did not stop with the company that was attacked. Healthcare providers and patients were also affected. This is important because sometimes cybersecurity can sound like it is only about protecting computers, but an attack on those computers can have a real impact on people who depend on the services they provide.
There is probably no way to completely guarantee that an organization will never be attacked, but there are ways to make an attack harder and reduce the damage if one happens. Organizations should use strong access controls and multi-factor authentication, keep systems updated, train employees on cyber threats, monitor their networks, and maintain secure backups. They should also have incident response, disaster recovery, and business continuity plans ready before something happens. Chai (2022) recommends practices such as redundancy, failover, network or server monitoring, and data recovery planning. Having these protections already in place can help an organization respond faster instead of trying to figure everything out in the middle of an attack.
Conclusion
Overall, the CIA Triad gives organizations a basic way to think about what they are trying to protect. Confidentiality keeps information away from unauthorized people, integrity makes sure the information can be trusted, and availability makes sure authorized users can access it when needed. Authentication and authorization support those goals by first verifying who a user is and then controlling what that user is allowed to access. The Change Healthcare attack shows how serious the consequences can become when these protections fail. For me, the biggest takeaway is that cybersecurity is not just about stopping hackers. It is also about making sure information stays private, accurate, and available so an organization can continue doing its job.