In this article, I will describe the three parts that make up the CIA triad along with an explanation of the differences between authentication and authorization with examples.
Confidentiality
The first letter of the triad and first concept that comes to mind when thinking of information security is confidentiality. Keeping accounts secure by way of passwords, OTPs, and biometrics reduces the number of people that have access to an account (GeeksforGeeks, 2019). A blog post on securityscorecard.com uses online shopping as an example of how the CIA triad is involved in everyday services (Fasulo, 2021). If you were to say, try to access your Amazon account to check your orders; you need to enter your password to verify that you’re someone who is supposed to have access to the information related to the account. Confidentiality is making sure that your credit card information, address, and phone number stay locked behind the confines of your account available to only you and Amazon.
Integrity
Integrity is defined as helping to “maintain the trustworthiness of data by having it in the correct state and immune to any improper modifications” (Kirkpatrick et al., 2024). Once you log in to your account, you want to check your orders to verify that you will be getting everything you purchased. Once you see the confirmation that your items will be shipped, you just witnessed how Amazon ensured data integrity. They made sure that there was no interference between the time of your payment and the confirmation of your purchase.
Availability
Amazon can be always accessed because of the systems and protocols they’ve designed for their service. Making sure that a service or data is accessible to authorized parties defines availability (Fasulo, 2021).
Authentication vs. Authorization
Say you’re working on a group assignment using Google Docs. To start working on the project, you’d need your group members to verify their email addresses so that you can send them a link to your document. You send them a link to the document, but they’re not able to see what’s on it. You then must now give them permission to edit and view the document. Authentication is the verification of a user’s identity (GeeksforGeeks, 2019). This is what was used when you verified with your group members what their email addresses were. Authorization is the distribution of permissions (GeeksforGeeks, 2019). This is what was used when you gave your group members access to view and edit the document. These two go hand in hand when trying to control the flow of access to information.
Conclusion
The CIA triad is an excellent model for data security measures. Organizations get an overview of a guide to follow to reduce the possibility of security breaches. Authentication ties into confidentiality by preventing others from accessing accounts or information without the proper access tools. Authorization sits under the availability category as content will only be available to those with proper credentials. All are necessary to maintain a safe cyber presence in an organization.
References
Fasulo, P. (2021, September 1). What is the CIA Triad? Definition, Importance, & Examples. SecurityScorecard. https://securityscorecard.com/blog/what-is-the-cia-triad/
GeeksforGeeks. (2019, June 6). Difference Between Authentication and Authorization. GeeksforGeeks. https://www.geeksforgeeks.org/computer-networks/difference-between-authentication-and-authorization/
Kirkpatrick, C., Aldabagh, H., & Bowman, C. (2024). Cybersecurity, technology and society: An interdisciplinary look at the field of cybersecurity