The CIA Triad

The CIA Triad is an important, useful and necessary model designed to guide certain policies and procedures for information security. It is typically used for information security for an organization or business. It is also sometimes referred to as the AIC Triad as a means to avoid confusing it with the Central Intelligence Agency (CIA). The CIA is broken down into three major components; Confidentiality, which is responsible for only authorized individuals being granted access or permission to modify the content or data that is being kept. Confidentiality measures are in place to prevent sensitive or private data from being accessed by those who do not have the proper authorization. This prevents data from falling into the wrong hands or from being freely accessed by those with malicious intentions. The next component is Integrity, which helps maintain the trustworthiness of data. This is done by ensuring the data being sent or transferred remains in the condition it is sent. Integrity keeps data immune from alterations or modifications, as data must not be changed during transit or altered by unauthorized individuals. The last component is Availability, meaning that authorized users can access data whenever it is deemed necessary. Data will be consistently accessible because the data will be properly maintained and stored in the appropriate hardware and technical infrastructure of a company. The core difference between Authentication and Authorization is that Authentication is the verification or “proving” of having Authorization. For example, when you go to log into your google account, you have to do log in authentication. This is typically done by confirming the log in through a one time passcode emailed or texted to your mobile phone or device. Authorization follows Authentication, determining the resources or actions that a user is allowed to access or use. An example of this is an employee reading a file created by the admin staff but being unable to delete it since the admin staff created the file in the first place. 

Leave a Reply

Your email address will not be published. Required fields are marked *