Write-Up: The CIA Triad

In this write-up, I will summarize the CIA Triad and explain the difference
between Authentication and Authorization. The description in this paper provides a good
understanding of the role that the CIA Triad plays in protecting companies’ data. It will
also explain authentication and authorization as they are both important in the IT world.

CIA Triad summary

The CIA Triad is a trio-level guide to creating guidelines for information security within companies. In other words, it’s the three main components that IT specialists should take into account when it comes to keeping important information safe. The first part of the CIA Triad is confidentiality, which ensures that information is accessed only by authorized individuals. Certain information is more important than others, so the security level can vary. Good ways for companies to ensure confidentiality are teaching authorized individuals how to take proper security measures, utilizing protection methods such as two-step verification, and restricting document travel. The next approach within the CIA Triad is Integrity, which ensures the information stays accurate and untouched. This can be achieved by implementing proper file permissions, having backup systems, creating a log that reports revisions, and employing integrity checkers. The last part of the Triad is availability, which is ensuring that the information is easily reachable when needed. Regularly updating and maintaining hardware/software, utilizing firewalls, having a proper disaster recovery plan, and keeping duplicates are all important in making sure information is available at all times. It should be noted that the CIA Triad and its components are always being updated and improved. But, if implemented correctly, and thoroughly, and kept up with following the CIA Triad will keep your company’s information properly secured.

Authorization VS. Authentication

Authorization and Authentication are both used to protect resources but are different in their own ways. A quote from Auth0.com says it best: “In simple terms, authentication is the process of verifying who a user is, while authorization is the process of verifying what they have access to” (Auth, n.d.). Authentication typically occurs before Authorization and usually requires the user to enter a set of credentials. An example of this would be having to enter your username and password to get into a confidential document. Authorization on the other hand is what permissions you have after authentication. Piggybacking off my authentication example, this would be whether you’re allowed to edit this document. These two words can often get mixed up and misused, but are very important, especially in the world of information security.

Conclusion

Overall, I believe that it’s essential that every company follows the information given by the CIA Triad or something similar. Poor information security can create a lot of problems in an organization, especially financially, which is why it’s important to invest in the proper measures. Authorization and Authentication both play key roles in securing and protecting information whether it’s for a company or yourself.

References

  1. Auth. (n.d.). Authentication vs. Authorization. Auth0 Docs.https://auth0.com/docs/get-started/identity-fundamentals/authentication-and-authorization

Leave a Reply

Your email address will not be published. Required fields are marked *