Key Takeaways - CIA Triad vs CIAS Model
- The CIA Triad (Confidentiality, Integrity, Availability) has been the foundational model for cybersecurity, but it was designed before IoT, OT and AI existed at scale.
- ComplianceForge introduced the CIAS Model in 2017, adding Safety as a fourth pillar to address technologies that can cause physical harm if compromised.
- Safety addresses the risk of death, injury, illness, or equipment damage and loss from technologies that could fail or be manipulated by threat actors.
- The CIAS model is now reflected in the Secure Controls Framework (SCF) and ComplianceForge documentation products.
- Applying CIAS to risk management provides a more complete picture of cybersecurity requirements across all technology types.
The New ModelConfidentiality, Integrity, Availability & Safety (CIAS) Model
The security of systems, applications and services must include controls and safeguards to offset possible threats, as well as controls to ensure confidentiality, integrity, availability and safety:
- CONFIDENTIALITY – This addresses preserving authorized restrictions on access and disclosure to authorized users and services, including means for protecting personal privacy and proprietary information.
- INTEGRITY – This addresses protecting against improper modification or destruction, including ensuring non-repudiation and authenticity.
- AVAILABILITY – This addresses timely, reliable access to data, systems and services for authorized users, services and processes.
- SAFETY – This addresses reducing risk associated with technologies that could fail or be manipulated by nefarious actors to cause death, injury, illness, damage to or loss of equipment.

Operationalizing CIASApplying The CIAS Model To Risk Management
When you overlay real-world examples onto the CIAS model, it becomes clear how the CIAS model can help communicate cybersecurity and data protection requirements.

Common QuestionsFrequently-Asked Questions
Here are answers to common questions about the CIA Triad and the CIAS model:
What is the CIAS model in cybersecurity?
The CIAS model stands for Confidentiality, Integrity, Availability and Safety. ComplianceForge published it in 2017 as a replacement for the traditional CIA Triad, adding safety as a fourth pillar. Safety addresses the risk that technologies could fail or be manipulated in ways that cause death, injury, illness, or damage to or loss of equipment. The CIAS model is now reflected in the Secure Controls Framework (SCF) and in our documentation.
Why add safety to the CIA triad?
Safety was added because the CIA Triad was designed before Internet of Things (IoT), Operational Technology (OT) and Artificial Intelligence (AI) existed at scale. When a compromised device can move physical equipment or make autonomous decisions, protecting data alone does not capture the full consequence of an attack. Without a safety component, the CIA Triad falls short of defining the full scope of cybersecurity.
How does NIST define confidentiality, integrity and availability?
NIST's glossary uses the statutory definitions from Title 44 of the U.S. Code. Confidentiality means preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information. Integrity means guarding against improper information modification or destruction, including ensuring information nonrepudiation and authenticity. Availability means ensuring timely and reliable access to and use of information. The CIAS model keeps these and adds safety.
Does the Secure Controls Framework use the CIAS model?
Yes, the CIAS model is reflected in the Secure Controls Framework (SCF) and in ComplianceForge documentation products. Under the SCRMS, which is the model for implementing the SCF, an entity can reasonably claim it is secure if it has implemented and operational defenses focused on confidentiality, integrity, availability and safety. That puts safety on equal footing with the three traditional CIA objectives when an organization judges whether it is secure.
What is an example of a safety risk in cybersecurity?
A safety risk exists when a compromised or malfunctioning technology could physically harm people or equipment, not just expose data. For example, manipulating an operational technology controller in a manufacturing plant could override operating limits and damage machinery or injure workers. Autonomous and AI-driven systems raise similar concerns. The CIAS model treats safety as its own category so organizations assess and control it directly instead of folding it into availability.