It helps teams describe what could be harmed, select appropriate safeguards, and assess the effect of a failure. The three objectives apply to information and the systems that store, process, or transmit it.
The required balance is contextual. Emergency services may place exceptional weight on availability; financial records may demand particularly strong integrity; sensitive personal or commercial information may require strict confidentiality. A sound design considers all three without assuming they are equally important for every asset.
Key points
ConfidentialityPreserve authorized restrictions on access and disclosure. Controls may include access control, encryption, and careful data handling.
IntegrityGuard against improper modification or destruction and support confidence in authenticity. Controls may include digital signatures, change control, validation, and audit records.
AvailabilityProvide timely, reliable access to information and services. Controls may include redundancy, capacity planning, recovery arrangements, and denial-of-service protection.
Important limitationThe triad is a set of objectives, not a complete security program or a checklist of products. Privacy, safety, accountability, resilience, and usability may require additional analysis.