1.2 The CIA Triad Flashcards
1
Q
Explain the CIA Triad
A
- Combination of principles
– The fundamentals of security
– Sometimes referenced as the AIC Triad - Confidentiality
– Prevent disclosure of information to
unauthorized individuals or systems - Integrity
– Messages can’t be modified without detection - Availability
– Systems and networks must be up and running
2
Q
Explain Confidentiality
A
- Certain information should only be known
to certain people
– Prevent unauthorized information disclosure - Encryption
– Encode messages so only certain people
can read it - Access controls
– Selectively restrict access to a resource - Two-factor authentication
– Additional confirmation before information
is disclosed
3
Q
Explain Integrity
A
- Data is stored and transferred as intended
– Any modification to the data would be identified - Hashing
– Map data of an arbitrary length to data of a fixed length - Digital signatures
– Mathematical scheme to verify the integrity of data - Certificates
– Combine with a digital signature to verify an individual - Non-repudiation
– Provides proof of integrity, can be asserted to be genuine
4
Q
A