Forge University

Confidentiality, Integrity, and Availability (CIA Triad)

The CIA Triad — Confidentiality, Integrity, and Availability — is the foundational model for nearly every security control decision you will make as a CISSP, and it is the lens ISC2 expects you to apply throughout the exam.

Confidentiality ensures information is disclosed only to authorized subjects. Controls include encryption, access control lists, data classification, and need-to-know enforcement.

Integrity ensures data and systems are accurate, complete, and unaltered except by authorized action — covering data, system, and origin integrity. Hashing (SHA-256), digital signatures, version control, and change management all support integrity.

Availability ensures authorized users can access information and systems when needed. Redundancy (RAID, clustering, load balancing), fault tolerance, disaster recovery, and DDoS mitigation all serve availability.

The three elements pull against each other: strong encryption can slow processing and hurt availability; excessive change-control gates can delay legitimate access.

Worked scenario: A hospital's patient portal goes down during a ransomware attack that also encrypted backup files. Availability is the immediate failure, but integrity is also in question (data may have been altered before encryption), and confidentiality is at risk if data was exfiltrated first (double-extortion ransomware).

The Parkerian Hexad (Donn Parker) extends the triad with possession/control, authenticity, and utility — e.g., a stolen encrypted laptop keeps confidentiality intact but loses possession. Non-repudiation ensures a party cannot deny performing an action, achieved through digital signatures and audit logging.

Exam Tip: Map the described impact directly to C, I, or A before looking at answer choices.

Exam Tip: Data viewed but not changed = confidentiality violation, not integrity, regardless of how "damaging" the exposure is described.

Exam Tip: Watch for DAD (Disclosure, Alteration, Destruction) as the inverse of CIA framed from the attacker's side.

Knowledge check

Click an option to check yourself — this is a self-check, not graded or saved. The graded version pooling this module's questions is on the syllabus page.

1. A disgruntled employee copies a customer database to a USB drive but does not modify any records. Which element of the CIA Triad was violated?

2. Which control primarily supports data integrity?

3. A DDoS attack takes an e-commerce site offline for six hours. Which CIA element was most directly impacted?

4. A CISSP's laptop, fully protected with strong full-disk encryption, is stolen from a locked car. The security team confirms the encryption key was never compromised, so the thief cannot read any data on the drive. According to the Parkerian Hexad, which additional property beyond the CIA Triad was violated in this scenario?

5. Which set of terms correctly represents the 'DAD' model referenced as the inverse of the CIA Triad from an attacker's perspective?

6. A customer disputes a wire transfer, claiming they never authorized it. Which mechanism most directly provides the non-repudiation needed to resolve this dispute?

7. A company wants its database server to remain accessible to users even if a single physical disk fails. Which control category, described as supporting the Availability leg of the CIA Triad, should be implemented?

8. An attacker spoofs the email header of a company executive to trick an employee into wiring funds, but never alters the actual wording of the message after it is sent. Which aspect of integrity is most directly violated?

9. A developer pushes an unapproved code change directly to a production financial reporting system, bypassing the change advisory board. No data is viewed by unauthorized parties and the system stays online throughout. Which CIA Triad element does this scenario most directly threaten?

10. During an active service outage, a mandatory multi-day change advisory board review delays deployment of the emergency patch needed to restore the system. This situation illustrates a direct tension between which two elements of the CIA Triad?

11. A ransomware group exfiltrates a hospital's patient records before encrypting the production database, then threatens to publish the stolen data unless paid. Which two CIA Triad elements are most directly and unambiguously compromised by this double-extortion attack?

12. A company stores a fully encrypted backup tape offsite, but the only copy of the decryption key is destroyed in a fire along with the primary systems. The tape itself remains physically intact and reachable, but the data on it can never be read again. Which Parkerian Hexad property has been lost, distinct from availability?

Log in to chat with your AI Mentor about this lesson.