CIA Triad
The CIA Triad is a foundational model in information security built on three principles: confidentiality, integrity, and availability. It is commonly used to guide the design of policies and controls that protect data and keep systems secure and reliable. It describes core security goals rather than any single technology or regulatory requirement.
The CIA Triad is a model in information security comprising three pillars, confidentiality, integrity, and availability, used as a framework to guide the development of security policies and controls for protecting information and maintaining secure, reliable systems. It addresses the confidentiality, integrity, and availability dimension of information security and is distinct from data governance concerns such as data ownership, stewardship, quality, and lineage. The evidence provided does not detail specific implementation controls, threat categories, or how the model maps to particular legal or standards regimes, and those topics are out of scope for this entry.
Why it matters
The CIA Triad matters because it provides a shared vocabulary and structured lens for reasoning about what information security is actually meant to achieve. Rather than treating security as a loose collection of tools, the model frames it around three distinct goals, confidentiality, integrity, and availability, each of which can be threatened and protected in different ways. This helps teams evaluate whether a given control, policy, or design decision advances a specific security objective, and it surfaces trade-offs, since measures that strengthen one pillar can sometimes affect another.
For compliance and governance professionals, the Triad is useful as a conceptual anchor, but it should not be mistaken for a legal or regulatory requirement in itself. It describes security goals rather than obligations under any particular regime, and it does not by itself establish lawful bases, retention rules, or cross-border transfer mechanics. It is also distinct from data governance concerns such as ownership, stewardship, data quality, and lineage. The Triad addresses the confidentiality, integrity, and availability dimension of protecting information, and it is generally most valuable when used alongside, not in place of, governance and legal analysis.
Because the evidence supporting this entry describes the model at a conceptual level, it does not detail specific implementation controls, threat categories, or how the Triad maps to particular legal or standards frameworks. Practitioners should treat the model as a starting point for structuring their thinking and then look to applicable standards and jurisdiction-specific requirements to determine concrete obligations.
Who it's relevant to
Inside CIA
Common questions
Answers to the questions practitioners most commonly ask about CIA.