The CIA Triad is a model to guide policies for information security that consists of three main
parts: confidentiality, integrity, and availability. The CIA Triad plays a very important role between
ensuring information is secured but making sure it remains usable for authorized individuals.
CIA Triad Overview
The CIA Triad, also known as the AIC Triad, provides a framework for ensuring information is kept
secure but remains usable for anyone authorized access. It consists of three main parts:
confidentiality, integrity, and availability. Confidentiality makes sure that information is protected
from unauthorized access attempts. Integrity involves keeping data consistent, accurate, and
trustworthy. Lastly, availability involves information being accessible for authorized personnel.
The concept of the CIA Triad was formed over time and does not have a single creator but, “by
1998, people saw the three concepts together as the CIA Triad” (Chai, 2022, 7)
Authentication vs. Authorization
Authentication and authorization are two different but closely related concepts in information
security. Authentication involves the process of verifying identities of users to make sure they are
who they say they are before granting access to sensitive information. Authentication can take
many forms “like passwords, fingerprints, facial recognition, etc.” (Cawthra, 2020) in order to
authenticate an identity. Authorization is the process of granting or denying access to information
based on results of the authentication process. Authorization makes determinations whether you
have privileges to view, edit, delete, or add information. Therefore, authentication involves
verifying identities whereas authorization involves granting or denying rights to edit information.
Conclusion
The CIA Triad is an important framework for ensuring information is kept secure. Authentication
and authorization are two different but closely related concepts. Authentication involves
verification of identities while authorization is the process of granting or denying access to
information.
References
Cawthra, J. (2020, December). Executive Summary — NIST SP 1800-26 documentation. NCCOE.
Retrieved January 26, 2024, from
https://www.nccoe.nist.gov/publication/1800-26/VolA/index.html
Chai, W. (2022). What is the CIA Triad? Definition, Explanation, Examples – TechTarget.
TechTarget.
https://www.techtarget.com/whatis/definition/Confidentiality-integrity-and-availability-CIA?jr=on