Confidentiality
The first principle of the CIA Triad is confidentiality. If a security mechanism offers
confidentiality, it offers a high level of assurance that data, objects, or resources are
restricted from unauthorized subjects. If a threat exists against confidentiality,
unauthorized disclosure could take place.
In general, for confidentiality to be maintained on a network, data must be protected
from unauthorized access, use, or disclosure while in storage, in process, and in transit.
Unique and specific security controls are required for each of these states of data,
resources, and objects to maintain confidentiality.
Numerous countermeasures can help ensure confidentiality against possible threats.
These include encryption, network traffic padding, strict access control, rigorous
authentication procedures, data classification, and extensive personnel training.
Confidentiality and integrity depend on each other. Without object integrity,
confidentiality cannot be maintained. (Stewart et al., 2004)
Integrity
For integrity to be maintained, objects must retain their veracity and be intentionally
modified by only authorized subjects. If a security mechanism offers integrity, it offers a
high level of assurance that the data, objects, and resources are unaltered from their
original protected state. Alterations should not occur while the object is in storage, in
transit, or in process. Thus, maintaining integrity means the object itself is not altered
and the operating system and programming entities that manage and manipulate the
object are not compromised.
Integrity can be examined from three perspectives:
o Preventing unauthorized subjects from making modifications ;
o Preventing authorized subjects from making unauthorized modifications, such as
mistakes;
o Maintaining the internal and external consistency of objects so that their data is
a correct and true reflection of the real world and any relationship with any
child, peer, or parent object is valid, consistent, and verifiable.
Numerous attacks focus on the violation of integrity. These include viruses, logic bombs,
unauthorized access, errors in coding and applications, malicious modification,
intentional replacement, and system back doors. (Stewart et al., 2004)
Availability
The third principle of the CIA Triad is availability, which means authorized subjects are
granted timely and uninterrupted access to objects. If a security mechanism offers
Lebanese National Security Policy Guidelines v1.7
Page
14 |