The CIA Triad Write Up

The CIA Triad Write Up
Describe the CIA Triad, and the differences between Authentication & Authorization.
The CIA Triad is a core concept in the cyber security industry. It stands for Confidentiality, Integrity, and Availability. Confidentiality is the first pillar of the triad and it means can you keep the data private or limit access to those who need to see it. The next pillar is Integrity which asks if the data has been tampered with in anyway shape or form. The last pillar of the CIA Triad is Availability which asks if the data can be accessed when and where it needs to be. All three of these pillars make a safe and secure structure for data to be accessed.
Authentication and Authorization go hand and hand with one another but are not the same thing. Authentication is verification of one’s identity so logging into a computer with a username or password. While Authorization is the permissions of a user like creating files and being an Admin or normal user. Authentication has three traits (Fortinet) What they have, What they know, Who they are. Authorization is also defined by Fortinet “the process of giving a user permission to access a physical location or information-based resource”. While both of these are very similar they have subtle key differences and work together in combination to make cohesive security.

References:
Fortinet. Authentication vs Authorization: key Differences.
https://www.fortinet.com/resources/cyberglossary/authentication-vs-authorization

Leave a Reply

Your email address will not be published. Required fields are marked *