INFO 2004 Chap.6 Security Foundations and the CIA Triad
Security Foundations and the CIA Triad
Security begins with consequences, then moves to a precise definition and a method for reasoning about impact. The course uses a published cybersecurity definition from Schatz, Bashroush and Wall and connects it to the confidentiality, integrity and availability objectives in FIPS 199. Each objective is considered at low, moderate or high potential impact.
The aggregate security category takes the highest impact assigned to any objective, so a single high-impact consequence cannot be averaged away.
Because the source's impact table is licensed, this chapter rebuilds the method as an original decision path: identify the asset and affected stakeholder, describe the adverse effect of loss for each objective, select the qualitative level, justify it with scenario evidence, then carry the highest level into the aggregate result. The purpose is disciplined justification, not numerical risk calculation.
What this chapter covers
- 01
Why cybersecurity is a business priority
- 02
The cited cybersecurity definition
- 03
Confidentiality, integrity and availability
- 04
Low, moderate and high potential impact
- 05
Asset-by-asset scoring
- 06
The highest-impact aggregate rule
- 07
Turning a score into a treatment priority
Score a customer-order asset with the CIA method
- 1Confidentiality: exposure harms customer privacy and trust; justify the chosen qualitative level from that effect.
- 1Integrity: altered items or addresses can misdirect fulfilment and create financial and customer harm.
- 1Availability: temporary loss stops order processing; severity depends on duration and business dependence.
- 1Aggregate by selecting the highest of the three justified levels, never by averaging them.
Key terms
- Cybersecurity
- A published concept concerned with protecting cyberspace and the organisations and users who depend on it; keep the cited definition attached when quoting it.
- Confidentiality
- Preserving authorised restrictions on information access and disclosure.
- Integrity
- Guarding against improper information modification or destruction and supporting authenticity.
- Availability
- Ensuring timely and reliable access to and use of information.
- Potential impact
- A qualitative judgement—low, moderate or high—about the adverse effect caused by loss of a security objective.
- Aggregate category
- The overall category determined by the highest impact among confidentiality, integrity and availability.
Security Foundations and the CIA Triad FAQ
What are the three CIA objectives?
Confidentiality, integrity and availability.
How are impacts scored?
Each objective receives a low, moderate or high potential-impact judgement supported by scenario evidence.
How is the aggregate score calculated?
Use the highest of the three objective levels; do not average them.
Is the FIPS table reproduced here?
No. The licensed table is replaced by an original decision procedure and worked scenario.
Assessment move
Build practice cases around one named asset at a time. For each objective, write the loss event, the affected party, the adverse effect and the qualitative level. Then apply the highest-level rule. Swap only one scenario fact and re-score; this reveals which facts drive the judgement and prepares you to defend rather than merely announce a level.
Working through Security Foundations and the CIA Triad in INFO 2004? Sia is AskSia’s AI Computer Science tutor — ask any INFO 2004 Security Foundations and the CIA Triad question and get a clear, step-by-step explanation grounded in how INFO 2004 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.