{"id":290,"date":"2026-09-14T18:20:40","date_gmt":"2026-09-14T18:20:40","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/?p=290"},"modified":"2026-09-28T16:02:23","modified_gmt":"2026-09-28T16:02:23","slug":"the-understanding-of-cia-triad","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/2026\/09\/14\/the-understanding-of-cia-triad\/","title":{"rendered":"The Understanding of CIA Triad"},"content":{"rendered":"\n<p><strong>Introduction <\/strong><br>The CIA Triad is one of our foundational bases when it comes to cybersecurity. It is a simple framework that helps us understand how to navigate and protect the digital landscape. The CIA Triad is one of the foundational bases when it comes to cybersecurity. It is a simple framework that helps us understand how to navigate and protect the digital landscape. The CIA Triad focuses on three important principles: confidentiality, integrity, and availability (Fortinet, n.d.).  These principles help cybersecurity professionals understand how information should be protected and how information systems can remain secure and reliable. <\/p>\n\n\n\n<p><br><strong>What the CIA Triad means<\/strong><br> As previously stated, the CIA Triad is one of the guiding frameworks used to navigate and protect the digital landscape. Each concept is vitally important on its own, but they are also related to each other. Confidentiality, integrity, and availability each focus on a different part of protecting information and systems. On its core basis confidentiality is that one goes through to ensure that information remains private and confidential from those unauthorized to view. Integrity is insurance that the data has been protected and completely unaltered from the state during its prior authorized session. Availability is ensuring that the resources and data you need are available when you need them. <br>The culmination of these three concepts directly impacts cybersecurity as a profession. As the world becomes more and more digitalized these concepts are becoming vitally important to individuals, businesses, and governments. Cybersecurity and privacy are independent and separate disciplines and yet some of their objectives overlap and are complementary (National Cybersecurity Center of Excellence [NCCoE], n.d.).  The goal of cybersecurity\u2019s confidentiality is ultimately to protect information, systems, and data from unauthorized access or release.  <\/p>\n\n\n\n<p><br><strong>Confidentiality<\/strong><br>Cybersecurity\u2019s relationship with confidentiality is a serious one because protecting information requires cooperation from everyone involved. This includes the user, cybersecurity professionals, and the organization. Each person has a responsibility to help protect sensitive information and prevent unauthorized individuals from accessing it. Confidentiality does not exist in a bubble. It ultimately relies on a network of multiple systems and people to function correctly and smoothly. <\/p>\n\n\n\n<p><br><strong>Integrity<\/strong><br>Integrity&#8217;s place in the triad is a vital one as well. Once the data is out of your hands, everyone wants to be assured that the data is being held in a place where it has not been altered through malicious means. From there, it becomes the responsibility of the cybersecurity professional to develop ways to protect and safeguard the information so that it cannot be changed or replicated without authorization. This also means that the organization needs to follow government laws and ensure that proper storage and security practices are being followed. <br><br><strong>Availability<\/strong><br>Availability is, at its definition, the resources that are available to authorized users when they need them. This means that information and systems should be accessible when needed and should not take an unreasonable amount of time to retrieve. Cybersecurity professionals&#8217; role in this matter is to work in tandem with IT infrastructure to help make sure that these resources remain available to authorized users. This can include identifying misconfigurations in web browsers, network systems, and other parts of the IT infrastructure that could prevent users from accessing the resources they need. If an organization is not able to access the resources it needs, it can affect its ability to operate effectively.<\/p>\n\n\n\n<p><br><strong>The Impact of Cybersecurity Incidents<\/strong> <br> There are real-life impacts when the CIA Triad is compromised. A real-life example of this is the Pok\u00e9mon TeraLeak that happened in August 2024. This was thought to have been caused by a phishing and social engineering attack (Carpenter, 2024). At the time, information belonging to around 2,000 employees was stolen. Upcoming game plans and leaked concept pieces were also part of the information exposed from future Pok\u00e9mon games. This is a breach of confidentiality because employees&#8217; personal information was exposed, along with information that was not intended to be publicly available. This could also lead to potential copyright infringement and other long-term issues, such as future distrust when it comes to the company&#8217;s security measures. <\/p>\n\n\n\n<p><br> The first step to addressing this type of situation is providing employees with phishing training. Social engineering training is crucial in helping employees recognize and prevent future phishing attacks from happening again. Another approach could be filtering emails more closely and putting more safeguards in place. These safeguards could help prevent suspicious emails from reaching employees in the first place and reduce the chances of another successful attack. <br><br><strong>Conclusion<\/strong><br> The CIA Triad shows that cybersecurity is more than just preventing unauthorized access to information. Although it is a simple framework, it can also guide cybersecurity professionals to see where they may have faltered during an attack. It gives professionals a way to look back at an attack and understand what went wrong and what could have been done better. The Pok\u00e9mon TeraLeak is a good example of how one weakness can lead to the exposure of a large amount of information. This shows why it is important for cybersecurity professionals to not only focus on stopping an attack, but also on learning from what happened and making changes to prevent it from happening again. <br><br><strong>References<\/strong><br>GeeksforGeeks. (2026, March 31). Authentication vs authorization. GeeksforGeeks <br>Washington University in St. Louis, Office of Information Security. (n.d.-a). Availability. https:\/\/informationsecurity.wustl.edu\/items\/availability\/<br>Washington University in St. Louis, Office of Information Security. (n.d.-b). Confidentiality. https:\/\/informationsecurity.wustl.edu\/items\/confidentiality\/<br>Washington University in St. Louis, Office of Information Security. (n.d.-c). Confidentiality, integrity, and availability: The CIA triad. https:\/\/informationsecurity.wustl.edu\/guidance\/confidentiality-integrity-and-availability-the-cia-triad\/<br>Washington University in St. Louis, Office of Information Security. (n.d.-d). Integrity. https:\/\/informationsecurity.wustl.edu\/items\/integrity\/<br>Fortinet. (n.d.). What is the CIA triad and why is it important? https:\/\/www.fortinet.com\/resources\/cyberglossary\/cia-triad <br>National Cybersecurity Center of Excellence. (n.d.). Relationship between cybersecurity and privacy. National Institute of Standards and Technology. https:\/\/www.nccoe.nist.gov\/relationship-between-cybersecurity-and-privacy <br>Chapple, M. (2019, October 10). Privacy vs confidentiality vs security: What&#8217;s the difference? EdTech Magazine. https:\/\/edtechmagazine.com\/higher\/article\/2019\/10\/security-privacy-and-confidentiality-whats-difference <br>Thoropass. (2026). What is integrity in cybersecurity? Thoropass <br>Carpenter, N. (2024, October 15). How do video game companies like Game Freak keep getting hacked? Polygon. https:\/\/www.polygon.com\/analysis\/465967\/pokemon-game-freak-nintendo-hack-leak <br><br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The CIA Triad is one of our foundational bases when it comes to cybersecurity. It is a simple framework that helps us understand how to navigate and protect the digital landscape. The CIA Triad is one of the foundational bases when it comes to cybersecurity. It is a simple framework that helps us understand&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/2026\/09\/14\/the-understanding-of-cia-triad\/\">Read More<\/a><\/div>\n","protected":false},"author":32714,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":true,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/posts\/290"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/users\/32714"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/comments?post=290"}],"version-history":[{"count":2,"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/posts\/290\/revisions"}],"predecessor-version":[{"id":300,"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/posts\/290\/revisions\/300"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/media?parent=290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/categories?post=290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/karenfmadrigal\/wp-json\/wp\/v2\/tags?post=290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}