SaveMyCert
Cloud basics

What is the CIA triad? Confidentiality, integrity and availability

The CIA triad is the model of three core goals that underpin information security: Confidentiality (only authorised people can access data), Integrity (data stays accurate and unaltered) and Availability (systems and data are accessible when needed). Almost every security control exists to protect at least one of the three, which makes the triad the most useful starting framework for thinking about security at all. This article explains each goal with a plain example, the controls that support it, and why the three can pull against each other.

Confidentiality: only the right people can see it

Confidentiality means information is accessible only to those authorised to see it. A medical record that only the patient and their clinicians can read is confidential; one exposed to the public is not. The main controls are encryption, which makes data unreadable without the right key, and access control, which limits who can reach it in the first place.

Our what is encryption in the cloud explainer covers the first, and our what is identity and access management article covers the second.

Integrity: the data is accurate and unaltered

Integrity means data remains correct and has not been changed in an unauthorised or accidental way. If a bank balance or a software download is silently altered, integrity has failed even if nobody saw anything they should not. Supporting controls include hashing and checksums, which reveal whether data has changed, digital signatures, version control, and permissions that restrict who can modify data.

Availability: it works when you need it

Availability means systems and data can be reached by authorised users when they need them. A website that is down, or files locked by an attack, have failed on availability. The controls are redundancy so one failure does not stop service, backups and tested recovery, and protection against denial-of-service attacks that try to overwhelm a system.

Threats map neatly onto the triad: our what is ransomware article is an availability story, as it locks your data away.

The triad at a glance

Each goal has a plain question behind it and a typical set of supporting controls:

  • Confidentiality — can anyone who should not see this, see it? Encryption and access control.
  • Integrity — can I trust this data is correct and unchanged? Hashing, checksums, digital signatures, version control.
  • Availability — can authorised users reach it when needed? Redundancy, backups, DDoS protection.

When the goals pull against each other

The three goals can be in tension, so security is about balance rather than maximising one. Tightening access improves confidentiality but can make data harder to reach for the people who need it, hurting availability. Keeping everything open and instantly accessible does the reverse. Good security decisions weigh what matters most for the data in question. The triad is a core idea in our what is cloud security article, and it opens most introductory syllabuses, including ISC2 Certified in Cybersecurity and the AWS Certified Security – Specialty; our /revision library covers that syllabus lesson by lesson.

Ready to start studying — free?

Original practice questions, timed mock exams and revision notes. No card, nothing to pay.

Jump straight into an exam
SCS-C03CC

Questions, answered

In cybersecurity, CIA stands for Confidentiality, Integrity and Availability. It is a model of the three core goals of information security, and has nothing to do with the intelligence agency.

Sources

Exam details in this post come from the vendor's published exam guide, which is the authority on what is tested and how.

Keep reading

Cloud basics
ALB vs NLB: which AWS load balancer should you use?
Cloud basics
BigQuery vs Snowflake: which cloud data warehouse?
Cloud basics
Databricks vs Snowflake: what’s the actual difference?
Cloud basics
Horizontal vs vertical scaling: what is the difference?