CIA triad

The CIA triad is a foundational model in information security, built on three properties a system should protect: confidentiality, integrity, and availability. Organizations use it as a lens for setting security policy, assessing risk, and deciding how to protect data and systems.

The triad gives security teams a simple way to find vulnerabilities and to reason about the trade-offs between protecting data and keeping it usable. Tightening one property, such as confidentiality, often comes at some cost to another, such as availability. It underpins major standards and frameworks in the field, including ISO/IEC 27000 and the guidance published by NIST.