| |

LFCA 93 ๐Ÿง Security Fundamentals โ€” CIA Triad

Every security decision an organization makes โ€” which firewall to deploy, how to encrypt a disk, whether to buy redundant servers โ€” traces back to three fundamental goals. These three goals form the CIA Triad, the foundational model for information security. The LFCA exam places this topic under Security Fundamentals, which carries 14% of the total weight. The competency list includes “Security,” “Sensitive Data,” and “Compliance” . The CIA Triad is the lens through which every other security concept is understood.

Key point: The CIA Triad is not a checklist. It is a trade-off model. Every security control strengthens one or two of the three pillars, often at the expense of another. Encrypting a database strengthens confidentiality but can slow performance, which weakens availability. Aggressive multi-region replication strengthens availability but widens the surface where confidentiality could leak . Most security decisions are negotiations among the three, weighted by the value of the asset being protected.


Why the CIA Triad exists

Security is not a single property. It is a collection of properties that must be balanced. Without a framework, security decisions are ad hoc. The CIA Triad provides the framework.

The classification problem. Every piece of data has a different value and a different set of threats. A public marketing brochure does not need the same protection as a database of customer credit card numbers. The CIA Triad forces the organization to classify its data and apply controls proportional to the risk .

The communication problem. Security incidents are complex. The CIA Triad provides a common vocabulary. “This is a confidentiality breach” means something specific. It tells the incident response team, the legal department, and the public what happened and what the impact is .

The trade-off problem. Security controls are not free. They cost money, they add complexity, and they slow things down. The CIA Triad makes the trade-offs explicit. A control that strengthens confidentiality but weakens availability must be justified by the value of the data being protected .

The completeness problem. The CIA Triad is not the only model. Donn Parker’s Parkerian Hexad adds Possession/Control, Authenticity, and Utility . Frameworks like ISO/IEC 27001 and the NIST CSF layer on Authentication, Authorization, Non-repudiation, and Privacy. But the CIA Triad remains the starting point because its simplicity is its strength .

The trade-off. The CIA Triad is incomplete. It does not address non-repudiation, authenticity, or possession. It does not prescribe specific controls. It is a thinking tool, not a solution. But it is the thinking tool that every other security framework builds on.


a. Confidentiality

Confidentiality ensures that information is accessible only to authorized parties. Data should not be read or accessed without permission . Attacks against confidentiality are disclosure attacks .

The threats to confidentiality are external attacks like hacking and phishing, internal threats from malicious insiders, and accidental data exposure. A single misconfigured cloud storage bucket can expose millions of records. The 2017 Equifax breach, which exposed approximately 147 million records, is a pure confidentiality failure .

The controls that protect confidentiality include:

Encryption. Data is unreadable without the decryption key. Encryption protects data at rest (on disk) and in transit (over the network) .

Access control. Only authorized users can access the data. This includes authentication (verifying identity) and authorization (verifying permission) .

Data classification. Information is labeled by sensitivity. Public, internal, confidential, and highly confidential are common levels. The label determines the handling requirements .

Data masking. Sensitive fields are obscured in non-production environments. A test database might show “XXXX-XXXX-XXXX-1234” instead of the real credit card number .

The principle of least privilege is central to confidentiality. Users should have the minimum access needed to perform their job functions .


b. Integrity

Integrity ensures that data is accurate, complete, and unaltered. Data should not be modified or compromised in any way. It assumes that data remains in its intended state and can only be edited by authorized parties . Attacks against integrity are alteration attacks .

The threats to integrity are deliberate tampering, human error, and system faults. A supply-chain attack like SolarWinds SUNBURST (2020) is an integrity failure: signed, trusted software carried malicious code. The attackers modified the software without authorization, and the modification was not detected until much later .

The controls that protect integrity include:

Hashing and checksums. A hash function produces a fixed-length value from the data. If the data changes, the hash changes. The hash is a fingerprint. If the fingerprint does not match, the data has been altered .

Digital signatures. A signature proves that the data came from a specific source and has not been altered. The signature is created with the sender’s private key and verified with the public key .

Version control. Every change is recorded with an author, a timestamp, and a commit message. The history is the audit log. Git is the standard tool .

Write protection. Data is stored on read-only media or with permissions that prevent unauthorized writes .

Change management. Every change to a system goes through a defined process: request, review, approval, implementation, and verification .

The 2017 Equifax breach is also an integrity failure in one sense: the attackers modified records. But the primary failure was confidentiality. The distinction matters for understanding the scope of the incident .


c. Availability

Availability ensures that data and systems are accessible when authorized users need them. Data should be accessible upon legitimate request . Attacks against availability are destruction attacks .

The threats to availability are ransomware, distributed denial-of-service (DDoS) attacks, hardware failures, power outages, and infrastructure disruption. Ransomware is primarily an availability and integrity attack: the files are encrypted in place, making them inaccessible, and the attacker demands payment for the decryption key .

The controls that protect availability include:

Redundancy. Multiple copies of data and multiple paths to services. If one server fails, another takes over .

Backups. Regular backups stored offline or in immutable storage. The 3-2-1 rule applies: three copies, two media types, one off-site .

Disaster recovery. A documented plan for restoring services after a major disruption. The plan is tested regularly .

DDoS protection. Services that absorb or filter malicious traffic. Content delivery networks and specialized DDoS mitigation services are common .

Capacity planning. Ensuring that the infrastructure can handle peak load. Load and stress tests verify the capacity .

The 2024 CrowdStrike outage is a pure availability failure. A faulty update caused millions of Windows systems to crash. The systems were not breached and the data was not altered, but the services were unavailable .


Complete Example Session

This session demonstrates the CIA Triad through a practical scenario: a hospital patient records system.

# ============================================
# PART 1: THE ASSET
# ============================================

# The asset is a database of patient health records.
# It contains Protected Health Information (PHI).
# It is subject to HIPAA regulations.
# The impact of a breach is severe.

# ============================================
# PART 2: CONFIDENTIALITY CONTROLS
# ============================================

# Encryption at rest
# The database files are encrypted with AES-256.
# A stolen disk drive is unreadable without the key.

# Encryption in transit
# All connections use TLS 1.3.
# Eavesdropping on the network does not reveal the data.

# Access control
# Only doctors and nurses with a need-to-know have access.
# Role-based access control (RBAC) assigns permissions by role.
# Multi-factor authentication (MFA) verifies identity.

# Data classification
# Patient records are classified as "Highly Confidential."
# The classification triggers the strongest controls.

# ============================================
# PART 3: INTEGRITY CONTROLS
# ============================================

# Hashing
# Each record has a SHA-256 hash.
# Any modification to the record changes the hash.
# The hash is verified periodically.

# Digital signatures
# Prescriptions are digitally signed by the prescribing doctor.
# The signature proves the prescription came from that doctor
# and has not been altered.

# Audit logging
# Every access and every modification is logged.
# The log records who, what, when, and where.
# The log is immutable.

# Change management
# All changes to the database schema go through a review process.
# The change is tested in a staging environment first.

# ============================================
# PART 4: AVAILABILITY CONTROLS
# ============================================

# Redundancy
# The database runs on a primary server and a standby server.
# If the primary fails, the standby takes over automatically.

# Backups
# Full backups run nightly.
# Incremental backups run hourly.
# Backups are stored in a separate data center.
# Backups are tested quarterly.

# Disaster recovery
# The DR plan is documented and tested annually.
# The recovery time objective (RTO) is 4 hours.
# The recovery point objective (RPO) is 1 hour.

# DDoS protection
# The hospital network uses a DDoS mitigation service.
# The service filters malicious traffic before it reaches the servers.

# ============================================
# PART 5: THE TRADE-OFFS
# ============================================

# Encryption vs performance
# Encryption adds CPU overhead.
# The database queries are slightly slower.
# The trade-off is acceptable because the data is PHI.

# Redundancy vs cost
# The standby server doubles the hardware cost.
# The trade-off is acceptable because downtime is unacceptable.

# Access control vs usability
# MFA adds a step to the login process.
# The trade-off is acceptable because the data is sensitive.

# ============================================
# PART 6: THE DAD TRIAD
# ============================================

# The DAD Triad maps to the CIA Triad:
# Disclosure โ†’ Confidentiality
# Alteration โ†’ Integrity
# Denial โ†’ Availability

# Every attack can be classified by which CIA property it violates.
# The classification determines the appropriate response.

# ============================================
# PART 7: THE THREAT MODEL
# ============================================

# Threat: Ransomware
# Violates: Availability and Integrity
# Control: Immutable backups, endpoint protection, user training

# Threat: Data breach
# Violates: Confidentiality
# Control: Encryption, access control, network segmentation

# Threat: Supply chain attack
# Violates: Integrity
# Control: Provenance attestation, reproducible builds, vendor review

# ============================================
# PART 8: THE INCIDENT RESPONSE
# ============================================

# A ransomware attack is detected.
# The incident response team is activated.

# Step 1: Identify
# Which CIA property is violated?
# Availability is violated. The data is encrypted.
# Integrity is violated. The files are altered.

# Step 2: Contain
# Isolate the affected systems.
# Prevent the ransomware from spreading.

# Step 3: Eradicate
# Remove the ransomware.
# Patch the vulnerability that allowed the entry.

# Step 4: Recover
# Restore from the immutable backups.
# Verify the integrity of the restored data.

# Step 5: Learn
# Document the incident.
# Improve the controls.
# Train the users.

# ============================================
# PART 9: THE COMPLIANCE CONTEXT
# ============================================

# HIPAA requires:
# Confidentiality: Encryption, access control
# Integrity: Audit controls, authentication
# Availability: Contingency planning, backups

# The CIA Triad is the foundation of the compliance framework.
# Every control maps to one of the three pillars.

# ============================================
# PART 10: THE CIA TRIAD SUMMARY
# ============================================

# Confidentiality: prevent unauthorized disclosure
#   Controls: encryption, access control, classification

# Integrity: prevent unauthorized alteration
#   Controls: hashing, signatures, audit logs, change management

# Availability: prevent denial of access
#   Controls: redundancy, backups, DDoS protection, DR planning

# The three pillars are interdependent.
# Strengthening one can weaken another.
# The balance is determined by the value of the asset.

The ten parts cover the asset, confidentiality controls, integrity controls, availability controls, the trade-offs, the DAD Triad, the threat model, the incident response, the compliance context, and the summary.


Quick Reference

The Three Pillars

PillarDefinitionAttack Type
ConfidentialityOnly authorized accessDisclosure
IntegrityOnly authorized modificationAlteration
AvailabilityAccessible when neededDenial

The Controls by Pillar

PillarControls
ConfidentialityEncryption, access control, data classification, masking
IntegrityHashing, digital signatures, version control, audit logs
AvailabilityRedundancy, backups, DDoS protection, disaster recovery

The DAD Triad

DADCIAExample
DisclosureConfidentialityEavesdropping
AlterationIntegrityUnauthorized database change
DenialAvailabilityDDoS attack

The Trade-offs

Control StrengthensMay Weaken
Encryption (C)Performance (A)
Redundancy (A)Confidentiality surface (C)
Access control (C)Usability (A)

Best Practices

โœ… Do This:

# Encrypt sensitive data at rest and in transit
# Protects confidentiality                                            # โœ…
# Use hashing and digital signatures
# Protects integrity                                                  # โœ…
# Maintain offline, immutable backups
# Protects availability                                               # โœ…
# Classify data by sensitivity
# Determines the appropriate controls                                 # โœ…

โŒ Don’t Do This:

# Don't rely on a single control
# Defense in depth is required                                        # โŒ
# Don't store encryption keys with the data
# The key must be separate                                            # โŒ
# Don't skip backup testing
# A backup that cannot be restored is not a backup                    # โŒ

Common Pitfalls

PitfallWhy It HappensFix
Confidentiality breachNo encryption, weak access controlEncrypt, enforce least privilege
Integrity breachNo hashing, no audit logsAdd hashing, enable logging
Availability breachNo backups, no redundancyBack up, add redundancy
Trade-off ignoredControl added without assessmentEvaluate the balance

Real-World Examples

1. Confidentiality Control

# Encrypt the database with AES-256

2. Integrity Control

# Hash each record with SHA-256

3. Availability Control

# Run a primary and standby database

4. Data Classification

# Label the data as "Highly Confidential"

5. Access Control

# Role-based access with MFA

6. Ransomware Response

# Restore from immutable backups

7. DDoS Protection

# Use a DDoS mitigation service

8. Change Management

# Review and approve every change

9. Disaster Recovery

# Test the DR plan annually

10. Compliance

# Map controls to HIPAA requirements

Visual

The CIA Triad

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  CONFIDENTIALITY                             โ”‚
โ”‚    โ””โ”€ Only authorized access                 โ”‚
โ”‚       โ”‚                                      โ”‚
โ”‚  INTEGRITY โ”€โ”€โ”€โ”ผโ”€โ”€โ”€ AVAILABILITY              โ”‚
โ”‚    โ””โ”€ Only authorized modification           โ”‚
โ”‚                    โ””โ”€ Accessible when needed โ”‚
โ”‚                                              โ”‚
โ”‚  The three pillars are interdependent.       โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The DAD Triad

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  DISCLOSURE โ”€โ”€> CONFIDENTIALITY              โ”‚
โ”‚  ALTERATION โ”€โ”€> INTEGRITY                    โ”‚
โ”‚  DENIAL     โ”€โ”€> AVAILABILITY                 โ”‚
โ”‚                                              โ”‚
โ”‚  Every attack violates one or more.          โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The Trade-offs

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  STRENGTHEN C โ”€โ”€> WEAKEN A                   โ”‚
โ”‚    (encryption slows performance)            โ”‚
โ”‚                                              โ”‚
โ”‚  STRENGTHEN A โ”€โ”€> WEAKEN C                   โ”‚
โ”‚    (replication widens exposure)             โ”‚
โ”‚                                              โ”‚
โ”‚  The balance depends on the asset.           โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

The Controls by Pillar

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  CONFIDENTIALITY                             โ”‚
โ”‚    Encryption, access control, classificationโ”‚
โ”‚                                              โ”‚
โ”‚  INTEGRITY                                   โ”‚
โ”‚    Hashing, signatures, audit logs           โ”‚
โ”‚                                              โ”‚
โ”‚  AVAILABILITY                                โ”‚
โ”‚    Redundancy, backups, DR, DDoS protection  โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Summary

ItemValue
CIA TriadConfidentiality, Integrity, Availability
ConfidentialityOnly authorized access
IntegrityOnly authorized modification
AvailabilityAccessible when needed
DAD TriadDisclosure, Alteration, Denial
Confidentiality controlsEncryption, access control, classification
Integrity controlsHashing, signatures, audit logs
Availability controlsRedundancy, backups, disaster recovery
Trade-offStrengthening one can weaken another
LFCA weightSecurity Fundamentals, 14%

Key takeaways:

  • The CIA Triad is the foundational model of information security. It defines three core goals: confidentiality, integrity, and availability. Every security control maps to one or more of these pillars .
  • Confidentiality ensures that data is accessible only to authorized parties. Encryption, access control, and data classification are the primary controls. Attacks against confidentiality are disclosure attacks .
  • Integrity ensures that data is accurate and unaltered. Hashing, digital signatures, audit logs, and change management are the primary controls. Attacks against integrity are alteration attacks .
  • Availability ensures that data and systems are accessible when needed. Redundancy, backups, disaster recovery, and DDoS protection are the primary controls. Attacks against availability are denial attacks .
  • The DAD Triad maps threats to the CIA Triad. Disclosure compromises confidentiality. Alteration compromises integrity. Denial compromises availability. Thinking in DAD helps select the right controls .
  • The three pillars pull against each other. Strengthening one can weaken another. Encryption strengthens confidentiality but can weaken availability. Replication strengthens availability but can weaken confidentiality. The balance is determined by the value of the asset .
  • The CIA Triad is the foundation for compliance frameworks. HIPAA, PCI-DSS, and ISO/IEC 27001 all build on the three pillars. Every control in these frameworks maps to confidentiality, integrity, or availability .

Remember: The CIA Triad is not a checklist. It is a thinking tool. Confidentiality protects against disclosure. Integrity protects against alteration. Availability protects against denial. Every security decision is a negotiation among the three. The value of the asset determines the balance. The controls are the mechanisms. The DAD Triad is the threat model. And the compliance frameworks are the implementation.


Stop using slow, ad-bloated tool sites! ๐Ÿคฎ

๐Ÿ”Ž Search “KandZ Tools” on Google to use many professional utilities for free.

KandZ.me is the ultimate minimalist hub for:
โœ… Finance (Mortgage, Interest, Inflation)
โœ… Tech (Base64, JSON, Dev Suite, IP)
โœ… Health (BMI, BMR, TDEE)
โœ… Productivity (Timer, Workspace, QR)

โšก๏ธ Fast & Private
๐Ÿ”’ No data leaves your device
๐Ÿ’Ž 100% Free

๐Ÿ”— Use it now: https://tools.kandz.me
๐Ÿ”– Bookmark itโ€”youโ€™ll need it later!