Almost every CISSP question can be traced back to a small set of security goals. The best known is the CIA triad: confidentiality, integrity and availability. When a scenario describes a control or an attack, ask which of these it protects or harms. That habit will help you eliminate wrong answers quickly across all eight domains, because a control that does not serve the goal the scenario is worried about is rarely the best answer.
Confidentiality means information is disclosed only to authorized people, processes and devices. Controls include encryption, access control lists, data classification and need-to-know. Threats include eavesdropping, shoulder surfing, misdirected email, social engineering and stolen laptops. Integrity means data and systems are protected from unauthorized or accidental change, and that any change can be detected. Hashes, digital signatures, input validation, change control and least privilege support integrity. Availability means authorized users get timely, reliable access when they need it. Redundancy, backups, patching, capacity planning, fault tolerance and denial-of-service protection all support availability.
The goals trade off against each other. Strong encryption with a lost key destroys availability. Replicating a system widely for availability increases the number of places data can leak. Strict change control protects integrity but can slow emergency fixes. Security design is about balancing these according to what the business values most. A hospital may rank availability of patient records above everything else, a bank may put integrity of balances first, and a defense contractor may put confidentiality first. The data owner's priorities, not the security team's preferences, decide the balance.
The triad is not the whole story. Authenticity means you can verify that data or a message really comes from its claimed source and has not been altered along the way. Non-repudiation means a party cannot credibly deny having performed an action, such as sending a message or approving a payment. Non-repudiation usually requires a digital signature made with a private key that only the signer controls, backed by reliable logging and trusted timestamps. A shared secret, such as a symmetric key or a hash-based message authentication code (HMAC), gives integrity and authentication between two parties, but not non-repudiation, because either party could have produced it. A plain hash gives integrity only, because anyone can compute it.
Two related models appear often. The DAD triad (disclosure, alteration, destruction) is the attacker's view: each item is the opposite of one CIA goal. The Parkerian hexad adds possession or control, authenticity and utility to the triad; for example, an encrypted backup tape that is stolen is a loss of possession even if confidentiality holds. You may also see the extended goals of authentication, authorization and accountability, often called AAA. Remember that all of these goals apply to data at rest, in transit and in use, and to the systems and people around the data. A threat to availability might be a flood in the server room just as easily as a botnet.
Consider a worked example. A purchasing manager emails a supplier approving a large order, then later claims she never sent it. If the email was sent over an encrypted channel only, the company can prove confidentiality but not who wrote it. If both parties shared a secret key and used an HMAC, the supplier can show the message was not altered, but the manager can argue the supplier generated it. If the email was signed with the manager's private key, stored on a smart card that only she holds, and the signing event was logged with a trusted timestamp, the company has non-repudiation. Her denial is no longer credible.
Common mistakes: thinking encryption provides integrity by itself (only authenticated encryption modes do); treating a hash as proof of origin; assuming availability is not a security concern; and forgetting that non-repudiation depends on the private key being under the sole control of its owner. If a private key is shared among a team or copied onto several servers, the signatures lose their non-repudiation value.
Exam questions use clue words. 'Disclosure', 'eavesdropping' or 'leak' point to confidentiality. 'Modified', 'tampered' or 'unauthorized change' point to integrity. 'Outage', 'downtime' or 'flood' point to availability. 'Cannot deny', 'proof of origin' or 'legally binding' point to non-repudiation and digital signatures. Think like a manager: the best answer protects the goal the business cares about most in that scenario, at a reasonable cost, rather than maximizing every goal at once.
Key terms
- Confidentiality
- Assurance that information is disclosed only to authorized people, processes and devices.
- Integrity
- Assurance that data and systems are protected from unauthorized or accidental change, and that changes can be detected.
- Availability
- Assurance that authorized users have timely and reliable access to information and systems.
- Authenticity
- The property of being verifiably genuine, coming from the claimed source and unaltered.
- Non-repudiation
- Assurance that a party cannot credibly deny having performed an action, usually provided by digital signatures and logging.
- DAD triad
- Disclosure, alteration and destruction: the attacker-focused opposites of confidentiality, integrity and availability.
- Parkerian hexad
- A model that extends the CIA triad with possession or control, authenticity and utility.
An online brokerage requires customers to confirm large trades with a signing key stored in a hardware token. Months later a customer disputes a trade, saying he never placed it. The brokerage produces the signed order, the certificate linking the public key to the customer, and timestamped logs. Because only the customer controlled the private key, the signature provides non-repudiation, which a password or shared secret could not.
Check yourself
A ransomware attack encrypts a hospital's patient records. Which CIA goal is most directly harmed?
Availability, because authorized clinicians can no longer access the records when needed, although confidentiality may also be at risk if data was stolen.
Why does an HMAC not provide non-repudiation?
Both parties share the same secret key, so either could have generated the HMAC and the sender can plausibly deny creating it.
What is the attacker-oriented counterpart of the CIA triad?
The DAD triad: disclosure, alteration and destruction.
What condition must hold for a digital signature to provide non-repudiation?
The signer's private key must be under the signer's sole control, supported by trustworthy certificates, logging and timestamps.