City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Chap.1 Information Security, the CIA Triad and the Security Gap

- one subject, every graph, every model, every mark
7 Chapters3-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
Chapter 1 of 10 · IS6523

Information Security, the CIA Triad and the Security Gap

A definition built on balance, not on safety

The opening session defines information security as a considered confidence that an organisation's information risks and the controls are in balance, a phrasing credited to an industry practitioner in 2002. Nothing in it mentions technology and nothing in it describes being safe.

It describes an equilibrium, and every later session is a way of making one side of that equilibrium countable.

Risk identification and loss expectancy count the risks; firewalls, detection, access control and application controls make the controls concrete; cost benefit analysis is where the two halves meet.

Three characteristics, three different kinds of loss

Security itself is defined as protecting information together with its critical elements, meaning the systems and the machinery on which it is held, moved and used, and the confidentiality, integrity and availability triangle is named as the standard the field grew from, since expanded into a longer list of critical characteristics.

Treat the three as distinct failure modes rather than as a slogan.

Disclosure to a party with no entitlement, alteration that leaves a record usable but wrong, and absence at the moment the business needs it are three separate losses, and each is answered by a different control.

Why a business argument comes before any threat list

Before a single attack is described, the session names four functions information security performs for an organisation: protecting the ability to function, enabling the safe operation of applications running on its systems, protecting the data it collects and uses, and safeguarding the technology assets in use.

The ability to function comes first because it is the one an executive already cares about, and every recommendation in this course is addressed to somebody paying for it out of a budget with other claims on it.

In this chapter

What this chapter covers

  • 01

    Information security as a balance between risks and controls

  • 02

    Confidentiality, integrity and availability as three distinct losses

  • 03

    Security management as the narrowing of a gap

  • 04

    Risk against the cost of controls, and the floor beneath both

  • 05

    Security balanced against access, and why total protection fails

  • 06

    The four business functions security performs

  • 07

    Non-deterministic output as an integrity question

Worked example · free

Separate three losses that management called one breach

Q [6 marks]. AskSia-authored practice. A regional insurer reports three events in one quarter: policy records copied to a broker with no entitlement to them, a software update that silently rounded claim values for five weeks, and a power fault that took the claims portal offline for two days. Management calls all three a security breach and asks for one recommendation. The marks shown are an AskSia study allocation, not a University marking scheme.
  • 3Assign each event to one of the three characteristics.
  • 2Name the control that belongs to each.
  • 1Say why one recommendation would be the wrong deliverable.
The broker disclosure is a confidentiality loss and its control is authorisation, a review of which roles may extract policy records at all. The silent rounding is an integrity loss and its control is verification, because what left the building matters less than what remained having stopped being true. The outage is an availability loss, and availability is most often defended by something other than a security product, here conditioned power and a tested restart. One recommendation would buy one of the three controls and leave the other two exposures open, which is why naming the characteristic first is the whole of the method.
Sia tip — Write the characteristic before the control, in that order. If the same characteristic comes up twice in one incident, one of the two events has been misread: disclosure, alteration and absence are three different losses and they cannot share a remedy.
Glossary

Key terms

Confidentiality
The characteristic breached when information reaches a party with no entitlement to see it. Its controls are authorisation and encryption.
Integrity
The characteristic breached when information is altered so that it remains usable but is no longer true. It is the hardest of the three to detect after the fact.
Availability
The characteristic breached when information cannot be reached at the moment the business needs it. It is frequently defended by facilities rather than by security products.
Security Management
The strategies and actions, by means of security tools and countermeasures, taken to narrow the gap between current security practice and the standard set by policy.
Inherent Control Risk
The floor of risk that remains whatever is spent on controls. Its existence is why an acceptable level, rather than none, is the honest target.
Generative Model
A model that creates content rather than predicting a label. The course groups it with predictive models as the two main kinds of artificial intelligence and treats both as producing output that is not absolutely correct.
FAQ

Information Security, the CIA Triad and the Security Gap FAQ

Why does the course define security as a balance rather than as protection?

Because a balance has two measurable sides and a state of protection has none. Defining it as an assurance that risks and controls are in balance makes every later session a way of quantifying one side or the other, and it makes an answer checkable: a recommendation that names a control without naming what it is in balance against has only completed half the definition, which is precisely where most weak answers stop.

Is the three-characteristic triangle still the whole model?

No, and the session says so. It describes the confidentiality, integrity and availability standard as having been expanded into a longer list of critical characteristics of information. The three remain the right first cut because a loss is named that way before anything else happens, but an answer that treats them as exhaustive is repeating a model the course has already told you was extended.

Why is artificial intelligence introduced in a session about security fundamentals?

Because the difference the session draws between conventional and intelligent programming is an integrity question. A conventional program deterministically produces the single correct output from correct inputs and procedures, while an intelligent one deduces a set of possible solutions and filters or trains towards the most appropriate, so its output is not absolutely correct.

The group project makes that difference the centre of its assessment.

Can a system be described as secure in an answer for this course?

Not usefully. The vocabulary the course supplies is an asset protected to a stated level, at a stated cost, against a named threat, and the word secure without those three qualifiers asserts something neither an examiner nor a manager can assess. The same discipline applies to a vendor claim, and recognising it is worth marks in its own right.

Study strategy

Exam move

Take three incidents from any organisation you know and label each with one characteristic and one control before reading further. If two of them end up with the same label, look again, because the usual cause is that a single word such as breach has been allowed to cover two different losses.

Then draw the risk against cost picture from memory, with the floor included, and say in one sentence what the floor means for a target.

Working through Information Security, the CIA Triad and the Security Gap in IS6523? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Information Security, the CIA Triad and the Security Gap question and get a clear, step-by-step explanation grounded in how IS6523 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 3-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works