{"id":298,"date":"2026-04-28T02:21:23","date_gmt":"2026-04-28T02:21:23","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/?p=298"},"modified":"2026-04-28T02:21:23","modified_gmt":"2026-04-28T02:21:23","slug":"the-c-i-a-triad","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/2026\/04\/28\/the-c-i-a-triad\/","title":{"rendered":"The C.I.A. Triad"},"content":{"rendered":"\n<p>BLUF: The C.I.A. Triad, also known as Confidentiality, Integrity, and Availability, forms the<br>foundation of information security by keeping data private, accurate, and available, while<br>authentication and authorization ensure that access is properly verified and controlled.<br>What is the C.I.A. Triad<br>Confidentiality, Integrity, and Availability are the three fundamental principles that guide<br>information security within an organization. Beginning in the 1970s, these three principles<br>developed from a combination of different security concepts and eventually formed what is<br>known as the CIA triad (Chai, 2022). The triad is an essential tool that organizations use when<br>creating security policies, developing frameworks, and designing products and technologies to<br>protect their information.<br>Confidentiality<br>Confidentiality can easily be understood as privacy. It refers to the rules and practices that limit<br>access to information and ensure that only authorized individuals are allowed to view or modify<br>data. The goal of confidentiality is to protect sensitive information from being accessed by the<br>wrong people.<br>One important and often overlooked part of maintaining confidentiality is proper training.<br>Protecting data is not just about technology; it also requires educating employees on how to<br>handle information securely. Training helps authorized users understand how to safeguard data<br>and avoid common security mistakes, such as sharing passwords or clicking unsafe links (Chai,<br>2022). This can include creating strong passwords and using secure password practices. A<br>common example of a confidentiality measure is two-factor authentication (2FA), which adds an<br>extra layer of security beyond just a password. Other best practices include encrypting data and<br>regularly updating file permissions to ensure that only the right individuals have access (Chai,<br>2022).<br>Integrity<br>Integrity means keeping data accurate and consistent. It is important that information is not<br>changed or tampered without authorization to maintain trust. Organizations use different<br>measures to prevent unauthorized changes and protect data.<br>Some of these measures include setting up proper file permissions, using checksums, keeping<br>data logs, and applying version control to track changes (Chai, 2022). There are also systems that<br>detect if data has been altered by errors or unexpected events and allow it to be restored. Just like<br>confidentiality, employees must be trained and understand their role in maintaining data<br>integrity.<br>Availability<br>Availability is the principle that keeps systems running and accessible. It means making sure<br>data and services are ready and available to authorized users when they need them. For example,<br>if a website goes down and users cannot access it, the company can lose money and damage its<br>reputation. That is why availability is so important.<br>Maintaining availability includes performing hardware repairs, keeping operating systems and<br>software updated, and creating backup copies to prevent data loss. Organizations also use tools<br>and strategies like firewalls, failover systems, RAID, and business continuity plans to ensure<br>services continue even during unexpected disruptions (Chai, 2022).<br>Authentication VS. Authorization<br>Authentication is the process of verifying a user\u2019s identity. It confirms that a person\u2019s credentials<br>match the information stored in the system, ensuring that only authorized users can access a<br>protected network. A common example of authentication is Multi-Factor Authentication (MFA),<br>which requires more than one form of verification, such as a password and a code sent to a phone<br>(Frontegg, 2025).<br>Authorization happens after a user\u2019s identity has been verified. It determines what resources or<br>information the user is allowed to access. For example, Discretionary Access Control (DAC)<br>grants access based on specific policies. The key difference is that authentication verifies who<br>the user is, while authorization decides what the user is allowed to do (Frontegg, 2025).<br>Conclusion<br>In conclusion, the C.I.A. Triad (Confidentiality, Integrity, and Availability) provides the<br>foundation for protecting information within an organization. Each principle plays an important<br>role in maintaining a secure system. Confidentiality ensures that sensitive information is kept<br>private and only accessed by authorized individuals. Integrity focuses on keeping data accurate<br>and trustworthy by preventing unauthorized changes. Availability guarantees that systems and<br>data remain accessible when needed. In addition, authentication and authorization work<br>alongside these principles by verifying user identity and controlling access to resources.<br>Together, these concepts create a strong security framework that helps organizations protect their<br>data and establish long-term success.<br>References<br>Chai, W. (2022b, June 28). What is the CIA triad_ definition,<br>explanation, examples &#8211; techtarget.pdf. Google Drive.<br>https:\/\/drive.google.com\/file\/d\/1898r4pGpKHN6bmKcwlxPdVZpC<br>C6Moy8l\/view<br>Frontegg. (2025, November 5). Authentication vs authorization: Key<br>differences explained.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BLUF: The C.I.A. Triad, also known as Confidentiality, Integrity, and Availability, forms thefoundation of information security by keeping data private, accurate, and available, whileauthentication and authorization ensure that access is properly verified and controlled.What is the C.I.A. TriadConfidentiality, Integrity, and Availability are the three fundamental principles that guideinformation security within an organization. Beginning in the&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/veraofosuaa\/2026\/04\/28\/the-c-i-a-triad\/\">Read More<\/a><\/div>\n","protected":false},"author":32041,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/posts\/298"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/users\/32041"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/comments?post=298"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/posts\/298\/revisions"}],"predecessor-version":[{"id":299,"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/posts\/298\/revisions\/299"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/media?parent=298"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/categories?post=298"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/veraofosuaa\/wp-json\/wp\/v2\/tags?post=298"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}