{"id":299,"date":"2026-10-05T02:20:35","date_gmt":"2026-10-05T02:20:35","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/tammyrizo\/?page_id=299"},"modified":"2026-10-05T02:20:35","modified_gmt":"2026-10-05T02:20:35","slug":"the-cia-triad-the-structure-for-cybersecurity","status":"publish","type":"page","link":"https:\/\/sites.wp.odu.edu\/tammyrizo\/it-cyse-200t-2\/the-cia-triad-the-structure-for-cybersecurity\/","title":{"rendered":"The CIA Triad: The Structure for Cybersecurity"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">About This Write-Up<\/h2>\n\n\n\n<p>This professional write-up examines the CIA Triad\u2014confidentiality, integrity, and availability\u2014and how these principles provide a foundation for cybersecurity. I apply these concepts to the 2024 Change Healthcare cyberattack to demonstrate how a real-world incident can affect sensitive information and critical services. This assignment helped me connect the components and functions of cyber systems to security concerns and understand how cybersecurity incidents can affect organizations and the people who depend on their services.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The CIA Triad<\/h2>\n\n\n\n<p>The CIA Triad stands for confidentiality, integrity, and availability. These are the core principles of cybersecurity. Systems and data become vulnerable when these principles are not adequately protected. Understanding the CIA Triad, authentication and authorization, and lessons from real-world cybersecurity incidents can help organizations better protect their systems, information, and the people who depend on them.<\/p>\n\n\n\n<p>Chai (2022) explains that the CIA Triad consists of confidentiality, integrity, and availability and provides a model organizations can use when developing information security policies. An information system can remain vulnerable if one component of the CIA Triad is not adequately protected. Chai (2022) emphasizes that confidentiality, integrity, and availability should be viewed as interconnected rather than independent security goals.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Confidentiality <\/h3>\n\n\n\n<p>Confidentiality protects sensitive information from unauthorized access, or, more simply, keeps private information private. It is important because unauthorized access to sensitive information can compromise an individual&#8217;s privacy and create security risks for both individuals and organizations. Encryption, strong passwords, multi-factor authentication, and access controls are methods that can help maintain confidentiality (Chai, 2022). Online banking is an example of confidentiality in practice. Banks can use multi-factor authentication to verify a user&#8217;s identity. Encryption is used to protect sensitive information, and access controls can limit what information employees are authorized to view. These measures help protect customers&#8217; personal and financial information from unauthorized access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Integrity<\/h3>\n\n\n\n<p>Integrity ensures that information remains accurate, consistent, and trustworthy and that it is not improperly changed or deleted, or, more simply, that unauthorized tampering is not allowed. Integrity helps ensure that organizations maintain accurate information to make decisions and perform operations. Access controls, file permissions, logs, checksums, version control, and backups can help protect data integrity (Chai, 2022). A Man-in-the-Middle attack can compromise integrity when an attacker intercepts data in transit and secretly changes it before it reaches the receiver.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Availability<\/h3>\n\n\n\n<p>Availability ensures authorized users can reliably access information, systems, and services when needed, or, more simply, that systems are up and running when needed. Redundancy, monitoring, backups, disaster recovery, and business continuity planning can help maintain availability (Chai, 2022). Emergency services demonstrate the importance of availability. In an emergency, having reliable access to a person&#8217;s medical records can be critical for healthcare providers making decisions about patient care. Availability is important because organizations may be unable to perform critical operations if their systems become inaccessible.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Authentication and Authorization<\/h2>\n\n\n\n<p>Authentication and authorization are related and important in cybersecurity, but they have different purposes. Authentication verifies who a user is. For example, a user may enter a username and password to prove their identity. Multi-factor authentication strengthens authentication by requiring users to provide two or more different authentication factors. These factors include something you know, such as a password; something you have, such as a phone or security key; or something you are, such as a fingerprint.<\/p>\n\n\n\n<p>Authorization determines what an authenticated user is allowed to do or access. A parent may authenticate their identity, but that does not authorize them to access the same information as a principal, teacher, or student. Simply put, authentication verifies who you are, and authorization determines what you are allowed to do.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Change Healthcare Cyberattack<\/h2>\n\n\n\n<p>The February 2024 Change Healthcare ransomware attack shows how the CIA Triad applies to a real cybersecurity incident. During congressional testimony, UnitedHealth Group CEO Andrew Witty explained that attackers used compromised credentials to remotely access a Change Healthcare Citrix portal that lacked multi-factor authentication. After gaining access, the attackers moved laterally through the systems, exfiltrated data, and later deployed ransomware (Witty, 2024).<\/p>\n\n\n\n<p>The incident affected both confidentiality and availability. HHS&#8217;s Office for Civil Rights confirmed that the ransomware attack resulted in a breach of protected health information (U.S. Department of Health and Human Services [HHS], 2025). This represents a failure of confidentiality because unauthorized individuals gained access to sensitive information. The attack also affected availability. Systems were disconnected to contain the attack, disrupting healthcare organizations that depended on Change Healthcare&#8217;s services. Witty (2024) described impacts ranging from pharmacists manually submitting claims to healthcare practices struggling financially. HHS (2025) also described the attack as having an unprecedented impact on patient care and privacy. The incident shows how a cyberattack can affect an organization, its systems, and the individuals and other organizations that depend on its services.<\/p>\n\n\n\n<p>The attack also demonstrates the importance of risk management and defense-in-depth. Organizations cannot eliminate every cybersecurity threat, so they must identify valuable assets, recognize threats and vulnerabilities, evaluate their likelihood and potential impact, and apply appropriate controls to reduce risk. A remote-access system connected to sensitive healthcare information creates a significant risk. Allowing that system to operate without multi-factor authentication increased the risk that compromised credentials could lead to unauthorized access. Using multiple layers of security helps ensure that if one control fails, other controls remain in place to reduce risk.<\/p>\n\n\n\n<p>Additional layers of security can include least-privilege access, network segmentation, encryption, security monitoring, backups, and incident-response planning. These controls also support the CIA Triad: encryption and access controls help protect confidentiality; access controls, logs, checksums, and backups support integrity; and redundancy, backups, monitoring, and recovery planning support availability (Chai, 2022).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p>The CIA Triad provides a foundation for protecting information and organizational systems through confidentiality, integrity, and availability. Confidentiality protects information from unauthorized access. Integrity protects its accuracy and trustworthiness. Availability ensures authorized users can access information and systems when needed. Authentication verifies identity, while authorization determines what a user is allowed to access. The Change Healthcare attack demonstrates the importance of protecting all three components of the CIA Triad. It also shows why organizations should use risk management and defense-in-depth to protect information and maintain the services that people depend on.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">References<\/h2>\n\n\n\n<p>Chai, W. (2022, June 28). <em><a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/Confidentiality-integrity-and-availability-CIA\">What is the CIA triad? Definition, explanation, examples.<\/a> <\/em>TechTarget.<\/p>\n\n\n\n<p>U.S. Department of Health and Human Services. (2025, March 14).<em> <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/special-topics\/change-healthcare-cybersecurity-incident-frequently-asked-questions\/index.html\">Change Healthcare cybersecurity incident frequently asked questions.<\/a><\/em> Office for Civil Rights.<\/p>\n\n\n\n<p>Witty, A. (2024, May 1). <em><a href=\"https:\/\/www.congress.gov\/118\/meeting\/house\/117242\/witnesses\/HHRG-118-IF02-Wstate-WittyS-20240501-U5.pdf\">Testimony of Andrew Witty, chief executive officer, UnitedHealth Group, before the House Energy and Commerce Committee, Subcommittee on Oversight and Investigations: Examining the Change Healthcare cyberattack.<\/a> <\/em>U.S. House of Representatives.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>About This Write-Up This professional write-up examines the CIA Triad\u2014confidentiality, integrity, and availability\u2014and how these principles provide a foundation for cybersecurity. I apply these concepts to the 2024 Change Healthcare cyberattack to demonstrate how a real-world incident can affect sensitive information and critical services. This assignment helped me connect the components and functions of cyber&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/tammyrizo\/it-cyse-200t-2\/the-cia-triad-the-structure-for-cybersecurity\/\">Read More<\/a><\/div>\n","protected":false},"author":32737,"featured_media":0,"parent":133,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/299"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/users\/32737"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/comments?post=299"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/299\/revisions"}],"predecessor-version":[{"id":300,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/299\/revisions\/300"}],"up":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/pages\/133"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/tammyrizo\/wp-json\/wp\/v2\/media?parent=299"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}