Description should include
- identifying the goals within the confidentiality, integrity, and availability (CIA) triad and defining the terms as they apply to cybersecurity
- confidentiality―ensures that data are only accessed by authorized person(s) through security measures such as usernames and passwords and access control lists (ACL)
- integrity―ensures the data are trusted. This means data must be guarded against unauthorized changes; methods of ensuring integrity include data permissions and encryption
- availability―provides solutions to ensure that systems can be accessed when requested; this includes providing deploying system protections and proper hardware maintenance and system patching
- explaining that the CIA triad model provides the baseline standard of evaluating and implementing information security measures on any system
- stating that each component in the CIA triad has designated goals that provide distinct requirements, and that each goal provides an essential component of information security measures.
Additional components should include
- AAA framework
- authentication―verifies the user's identity (e.g., username and password, biometrics, or a security key)
- authorization―determines what the authenticated user is allowed to do (e.g., access files, use specific software).
- accounting―tracks user activity, such as login attempts, commands executed, and resource consumption, for auditing and monitoring.
- nonrepudiation―a cryptologic technique that provides the proof of the integrity and origin of data.
Teacher Resources: