StudyToCert

All certifications / CC / Lessons

ISC2 Certified in Cybersecurity 2026 outline · Domain 1: Security principles

Cybersecurity concepts: confidentiality, integrity, availability

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Almost every security decision you will study for the CC exam traces back to three goals, known together as the CIA triad: confidentiality, integrity and availability. When you are unsure what a control is for, ask which of these three it protects. When you are unsure how bad an incident is, ask which of the three was lost. The triad gives you a shared vocabulary for describing both problems and solutions.

Confidentiality means information is disclosed only to people, processes and devices that are authorized to see it. You protect it with access controls, encryption, data classification and training that teaches staff not to leave sensitive files in public places. Confidentiality is lost when a database is stolen, when someone reads a screen over your shoulder, or when an email with customer records goes to the wrong address. A closely related idea is sensitivity: the more harm disclosure would cause, the more protection the data needs.

Integrity means information and systems are accurate, complete and changed only in authorized ways. It covers data integrity (the payroll figures have not been altered), system integrity (the operating system has not been tampered with) and, in some texts, the integrity of the people and processes that handle data. Hashing lets you detect that a file changed, digital signatures show who produced it, and change management plus access control stop unauthorized edits in the first place. An attacker who changes a bank account number on an invoice has attacked integrity even if nothing was disclosed.

Availability means authorized users can get timely and reliable access to information and systems when they need them. Threats include denial-of-service attacks, hardware failure, power outages, ransomware that locks files and simple mistakes such as deleting the wrong virtual machine. Defenses include redundancy, backups, spare capacity, uninterruptible power supplies and tested recovery plans. Availability is judged against business need: a hospital record system that is down for ten minutes may be critical, while a marketing archive can wait a day.

The three goals can pull against each other. Encrypting everything and requiring several approvals improves confidentiality and integrity, but makes data slower to reach. Keeping many copies of data improves availability but creates more places it can leak. Good security finds the balance the business needs rather than maximizing one goal. The exam often describes a scenario and asks which principle is most affected, so practice naming the primary loss: leaked data is confidentiality, altered data is integrity, and unreachable data is availability.

You will also meet the opposite of CIA, sometimes called DAD: disclosure, alteration and destruction (or denial). It is simply the attacker's view of the same triad and can help you classify an attack quickly.

Key terms

Confidentiality
Keeping information from being disclosed to unauthorized people, processes or devices.
Integrity
Assurance that data and systems are accurate, complete and changed only in authorized ways.
Availability
Timely and reliable access to information and systems for authorized users.
Sensitivity
A measure of how much harm would result from unauthorized disclosure of information.
DAD triad
Disclosure, alteration and destruction or denial: the attacker-side opposites of confidentiality, integrity and availability.
Real-world example

A clinic's patient portal is hit three ways in one month: a misconfigured storage bucket exposes scanned records (confidentiality), a bug lets patients edit their own lab results (integrity), and a ransomware attack takes the scheduling system offline for two days (availability). Each incident needs different controls: access settings and encryption, input validation and change control, and offline backups with a recovery plan.

Exam tip: When a question asks which principle is affected, pick the one that was lost first and most directly. Ransomware that only encrypts files is primarily an availability problem; ransomware that also steals data adds a confidentiality loss.

Check yourself

An attacker changes the destination account number on a pending wire transfer. Which part of the CIA triad is primarily affected?

Integrity, because the data was altered without authorization; nothing was necessarily disclosed or made unavailable.

Which control mainly supports availability: encryption at rest, redundant power supplies, or file hashing?

Redundant power supplies, because they keep systems running when one component fails. Encryption supports confidentiality and hashing supports integrity.

Why can maximizing confidentiality hurt availability?

Extra layers such as encryption, approvals and strict access make it slower or harder for legitimate users to reach data, so controls must be balanced against business need.

Study CC for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CC study plan