The CIA Triad is made up of three key concepts: confidentiality, integrity and availability. These concepts provide organizations with primary policies to focus on when building or improving their information security programs.
The idea of confidentiality is to keep things secret from people who do not need to know certain things. Depending on the organization, the data or information they work with is usually categorized based of the harm it could do to the company if it was in the wrong hands (Chai, 2022). For example, in the military there are three main classifications of information: confidential, secret and top secret. Confidential information can do damage, secret could cause serious damage, and top secret could cause grave damage to the United States if given to the wrong person. An example of how information can be kept confidential to those who have a need to know is using two factor authentication, meaning that instead of just using a username and password to login some companies also require you to use a token, code, or fingerprint to gain access to systems.
Integrity is “guarding against improper information modification or destruction and ensuring information non-repudiation and authenticity” (Nieles, 2017). In other words, integrity is there to make sure information does not get changed and it is from who it says it is from. There are a lot of ways that people can ensure the messages sent are accurate and safe, in the military there is the concept of nonrepudiation meaning that someone cannot claim they didn’t send a specific email. To help prevent people from trying to claim something “wasn’t them” we have digital signatures attached to our common access cards and emails that show once I send an email my digital signature is attached to it. Some forms might also have file permissions on them to prevent people from making unnecessary changes.
Availability means that information is available and accessible at all times for those who requested it. There are a lot of different actions that can go into ensuring availability is met, such as, working to keep all computer systems updated and functioning properly. This can be done through software updates, equipment maintenance, vulnerability patches, etc. It also means that there are fail-safe plans in place to prevent there from being a single point of failure on systems or if a natural disaster was to occur that the systems would be protected from situations like that. Another way to ensure availability is met is making sure all employees accounts are updated regularly and functioning properly.
The concepts of authentication and authorization within the cybersecurity realm are all about helping keep our information secure. Authentication is making sure someone is who they say they are and is the first step in all security processes (Okta, 2024). Authorization is the act of giving someone access to the system or data requested after they have been authenticated. An example of how authentication and authorization works is in the Air Force. When trying to access a computer to complete my job duties I first will insert my CAC (common access card) into the computer and type in a personal pin number that only I would know. If the pin matches the CAC the computer will allow me to login, this is an example of authentication. The system recognizes that my personal pin does match the one listed with my credentials and says “yes this person is who they say they are.” Once I have logged into the computer, I can access the share drive for my specific work center because of the different security groups/privileges that are connected to my account; this is known as authorization. Because I have been authenticated by the system, I am allowed authorization to the specific items needed to complete my job.
The CIA triad, authentication, and authorization are some of they biggest key concepts in cybersecurity. They work as reminders of some of the most basic necessities in a system to ensure our data and information is safe and secure. By ensuring we have policies in place that meet each of these requirements we have the basics down for a good cybersecurity program.
References
Authentication vs. Authorization. Okta. (2024). https://www.okta.com/identity-101/authentication-vs-authorization/
Chai, W. (2022). What is the CIA Triad? Definition, Explanation, Examples. Tech Target. https://www.techtarget.com/whatis/definition/Confidentiality-integrity-and-availability-CIA?jr=on
Nieles, M., & Dempsey, K. (2017). An Introduction to Information Security. NIST. https://csrc.nist.gov/pubs/sp/800/12/r1/final