In cybersecurity, CIA stands for the Confidentiality, Integrity and Availability (the CIA Triad), forming the foundational principles for securing information.
The CIA Triad concept is meant to balance these principles as a “three-legged stool” where all three legs are needed, or the stool topples over.
In 2017, ComplianceForge published the Confidentiality, Integrity, Availability & Safety (CIAS) replacement for the traditional Confidentiality, Integrity & Availability "CIA Triad" that served as the traditional function of cybersecurity. With embedded technologies (e.g., Internet of Things (IoT) and Operational Technology (OT)) and the rise of Artificial Intelligence (AI) and autonomous technologies (AAT), the lack of a safety component makes the CIA Triad insufficient to define the concept of what cybersecurity is meant to perform.
The security of systems, applications and services must include controls and safeguards to offset possible threats, as well as controls to ensure confidentiality, integrity, availability and safety:
| Property | What it protects | Example controls |
|---|---|---|
| Confidentiality | Data is seen only by authorized people | Encryption, access control |
| Integrity | Data is accurate and changed only by authorized means | Hashing, change management |
| Availability | Systems and data are usable when needed | Backups, redundancy, DDoS protection |
For the full comparison, see CIA Triad vs CIAS Model.