The CIA Triad — Confidentiality, Integrity, and Availability — is the model most security controls, policies, and findings ultimately trace back to. When you're writing up a finding and trying to explain why it matters, one of these three is usually the answer.
Confidentiality
Information is only accessible to those authorized to see it. Controls that protect confidentiality include encryption at rest and in transit, access controls, and least-privilege permissions. A finding like "internal file share readable by all domain users" is a confidentiality issue — the data isn't corrupted or unavailable, it's just visible to people who shouldn't see it.
Integrity
Data and systems remain accurate and unaltered except by authorized action. Hashing, digital signatures, and change-control processes all exist to protect integrity. A finding like "no file integrity monitoring on production configs" is an integrity concern — someone could alter a config without anyone noticing.
Availability
Systems and data are accessible when needed by authorized users. This is what backups, redundancy, and DDoS protection are protecting against. A finding like "single point of failure on the authentication server" is an availability issue — nothing is being stolen or altered, but a failure takes down access for everyone.
Why it's worth knowing cold
Framing a finding in terms of C, I, or A (sometimes more than one at once) is what turns "this seems bad" into a clear statement of business risk — which is usually what actually gets a finding prioritized and fixed.
Most modern frameworks (CIS, NIST, ISO 27001) map their controls back to one or more of these three properties, even when it's not stated explicitly — it's worth getting in the habit of asking "which one of these does this control actually protect?" whenever you're evaluating a benchmark item.
Beyond the three — authentication, authorisation, and non-repudiation
The triad is the core, but three supporting properties come up constantly in findings, and naming them keeps you from forcing everything into C, I, or A:
- Authentication — proving an identity really is who it claims to be. A weak or missing authentication control (default credentials, no MFA on an external portal) is usually the gateway that later breaks confidentiality or integrity.
- Authorisation — deciding what an authenticated identity is allowed to do. Broken-access-control and privilege-escalation findings live here, and the damage they cause is normally described back in terms of C or I.
- Non-repudiation — ensuring an action can't later be denied, typically through tamper-evident logging and digital signatures. "Audit logging disabled on the domain controller" is a non-repudiation and integrity concern at the same time.
Authentication and authorisation are often abbreviated AuthN and AuthZ; combined with accounting (logging), they form the AAA model you'll see throughout network and identity products.