CIA Triad - Confidentiality, Integrity, and Availability Flashcards
Confidentiality
seeks to prevent the unauthorized disclosure of information
Integrity
seeks to prevent unauthorized modification of information
Availability
ensure authorized people can access the data they need, when they need to.
CIA Triad OR (AIC)
Confidentiality, Integrity, Availability
Availability - Threats
Malicious attacks (DDOS, physical, system compromise, staff) Application failures (error in the code) Component failure (hardware)
Availability - Defense
IPS/IDS
Patch Management
Redundancy on hardware power (Multiple power/supplies/UPS’/generators Disks (RAID), Traffic paths (network design), HVAC, staff, HA (high availability)
SLAs - How high uptime we want (99.%9) - ROI
Confidentiality
it keeps data secrets
Integrity
Seeks to ensure data that is written in an authorized manner is complete and accurate
Subject
An active entity on an information system
Object
a passive data file
Annualized Loss Expectancy
the cost of lose due to a risk over a year
Threat
a potentially negative occurrence
Vulnerability
a weakness in a system
Risk
a matched threat and vulnerability
Safeguard
a measure taken to reduce risk