The CIA Triad — Confidentiality, Integrity, and Availability — is the foundational model for nearly every security control decision you will make as a CISSP, and it is the lens ISC2 expects you to apply throughout the exam.
Confidentiality ensures information is disclosed only to authorized subjects. Controls include encryption, access control lists, data classification, and need-to-know enforcement.
Integrity ensures data and systems are accurate, complete, and unaltered except by authorized action — covering data, system, and origin integrity. Hashing (SHA-256), digital signatures, version control, and change management all support integrity.
Availability ensures authorized users can access information and systems when needed. Redundancy (RAID, clustering, load balancing), fault tolerance, disaster recovery, and DDoS mitigation all serve availability.
The three elements pull against each other: strong encryption can slow processing and hurt availability; excessive change-control gates can delay legitimate access.
Worked scenario: A hospital's patient portal goes down during a ransomware attack that also encrypted backup files. Availability is the immediate failure, but integrity is also in question (data may have been altered before encryption), and confidentiality is at risk if data was exfiltrated first (double-extortion ransomware).
The Parkerian Hexad (Donn Parker) extends the triad with possession/control, authenticity, and utility — e.g., a stolen encrypted laptop keeps confidentiality intact but loses possession. Non-repudiation ensures a party cannot deny performing an action, achieved through digital signatures and audit logging.
Exam Tip: Map the described impact directly to C, I, or A before looking at answer choices.
Exam Tip: Data viewed but not changed = confidentiality violation, not integrity, regardless of how "damaging" the exposure is described.
Exam Tip: Watch for DAD (Disclosure, Alteration, Destruction) as the inverse of CIA framed from the attacker's side.