Confidentiality, Integrity and Availability
In ISO/IEC 27001, information security rests on three core properties, the CIA triad, and the purpose of an Information Security Management System (ISMS) is to preserve them. ISO/IEC 27000 provides the formal definitions that auditors use. Confidentiality is the property that information is not mad… In ISO/IEC 27001, information security rests on three core properties, the CIA triad, and the purpose of an Information Security Management System (ISMS) is to preserve them. ISO/IEC 27000 provides the formal definitions that auditors use. Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities or processes. Controls that protect it include information classification, access control, encryption, non-disclosure agreements and secure disposal. A breach occurs, for example, when customer data is leaked or an employee views records beyond their role. Integrity is the property of accuracy and completeness. It means information and processing methods are not altered improperly, whether by accident or with malicious intent. Supporting controls include change management, input validation, checksums, digital signatures, segregation of duties and logging. Corrupted databases or unauthorized changes to financial records are typical integrity failures. Availability is the property of being accessible and usable on demand by an authorized entity. Relevant controls include backups, redundancy, capacity management, business continuity and ICT readiness planning, and protection against malware or denial-of-service attacks. System outages and ransomware that blocks access are examples of lost availability. The three properties depend on each other and must be balanced. Excessive confidentiality controls can reduce availability, while very high availability can increase exposure. Clause 6.1.2 of ISO/IEC 27001 requires the organization to identify risks associated with the loss of confidentiality, integrity and availability for information within the ISMS scope, and to assess their likelihood and consequences. The organization then selects Annex A controls to treat these risks and justifies them in the Statement of Applicability. Related properties such as authenticity, accountability, non-repudiation and reliability may also be considered. For a Lead Auditor, the CIA triad is a fundamental lens. The auditor verifies that the organization has identified its information assets and assessed CIA-related risks. The auditor also confirms that proportionate controls are implemented and gathers objective evidence that they operate effectively and are continually improved.
Confidentiality, Integrity and Availability (CIA Triad): A Complete ISO 27001 Lead Auditor Guide
Introduction
Confidentiality, Integrity and Availability, known as the CIA triad, are the foundation of information security and of every Information Security Management System (ISMS) built on ISO/IEC 27001. ISO/IEC 27000 defines information security as the preservation of confidentiality, integrity and availability of information. Every policy, risk assessment, control and audit finding in an ISMS can be traced back to protecting one or more of these three properties. For an ISO 27001 Lead Auditor, the CIA triad is not just theory. It is the lens used to judge whether an organization's risks are correctly identified, whether controls are relevant, and whether nonconformities actually affect information security.
Why the CIA Triad Is Important
1. It defines the purpose of the ISMS. ISO/IEC 27001 clause 6.1.2 c) 1) requires the organization to apply its information security risk assessment process to identify risks associated with the loss of confidentiality, integrity and availability for information within the scope of the ISMS. Without CIA there is no basis for risk identification.
2. It drives risk evaluation. The impact of a risk is usually rated by asking what happens if information is disclosed (C), altered or corrupted (I), or unavailable (A). Many organizations rate each asset separately on C, I and A.
3. It justifies control selection. Controls in Annex A of ISO/IEC 27001:2022 are chosen to treat risks to CIA. ISO/IEC 27002:2022 even tags each control with an information security properties attribute: Confidentiality, Integrity and/or Availability.
4. It gives auditors a consistent yardstick. When an auditor finds a weakness, the key question is: which property of information is threatened, and how seriously? This determines whether a finding is a major nonconformity, a minor nonconformity or an opportunity for improvement.
5. It connects business and technical language. Executives understand 'customer data leaked', 'invoices wrong' and 'website down'. These map directly to C, I and A, making the triad a bridge between management and IT.
What Each Element Means
Confidentiality
ISO/IEC 27000 definition: property that information is not made available or disclosed to unauthorized individuals, entities or processes.
In plain terms: only the right people (or systems) can see the information.
Typical threats: data breaches, eavesdropping, shoulder surfing, phishing that steals credentials, lost laptops or USB drives, misdirected emails, insider leaks, weak access rights.
Typical controls (ISO/IEC 27001:2022 Annex A): 5.12 Classification of information, 5.13 Labelling of information, 5.15 Access control, 5.18 Access rights, 6.6 Confidentiality or non-disclosure agreements, 7.7 Clear desk and clear screen, 8.3 Information access restriction, 8.5 Secure authentication, 8.10 Information deletion, 8.11 Data masking, 8.12 Data leakage prevention, 8.24 Use of cryptography.
Integrity
ISO/IEC 27000 definition: property of accuracy and completeness.
In plain terms: information is correct, complete and has not been altered in an unauthorized or accidental way.
Typical threats: unauthorized modification, data entry errors, software bugs, malware that alters files, uncontrolled changes, man-in-the-middle tampering, corrupted backups, fraud.
Typical controls: 5.3 Segregation of duties, 8.4 Access to source code, 8.15 Logging, 8.16 Monitoring activities, 8.25 Secure development life cycle, 8.28 Secure coding, 8.29 Security testing, 8.32 Change management, 8.24 Use of cryptography (hashing and digital signatures), 8.7 Protection against malware, input validation and reconciliation checks.
Availability
ISO/IEC 27000 definition: property of being accessible and usable on demand by an authorized entity.
In plain terms: authorized users can get to the information and systems when they need them.
Typical threats: hardware failure, power outages, natural disasters, denial-of-service (DoS/DDoS) attacks, ransomware, capacity overload, supplier failure, accidental deletion.
Typical controls: 5.29 Information security during disruption, 5.30 ICT readiness for business continuity, 7.11 Supporting utilities, 7.13 Equipment maintenance, 8.6 Capacity management, 8.13 Information backup, 8.14 Redundancy of information processing facilities, 5.22 Monitoring of supplier services.
Related Properties
ISO/IEC 27000 notes that information security can also involve other properties such as authenticity (an entity is what it claims to be), accountability, non-repudiation (the ability to prove an event or action occurred and by whom) and reliability (consistent intended behaviour and results). These are often seen as extensions of integrity, but in exam questions they are distinct terms. Know their definitions so you do not confuse them with the core three.
How the CIA Triad Works in an ISMS
Step 1: Context and scope (clauses 4.1 to 4.3). The organization identifies what information it holds and why it matters. Legal, regulatory and contractual requirements (clause 4.2) often set CIA expectations, for example privacy laws (confidentiality) or service-level agreements (availability).
Step 2: Policy and objectives (clauses 5.2 and 6.2). The information security policy commits to protecting CIA. Objectives are often CIA-linked, for example '99.9% system availability' or 'zero unauthorized disclosures of customer data'.
Step 3: Risk assessment (clause 6.1.2 and 8.2). For each asset or scenario, the organization asks: what is the impact if C, I or A is lost, and how likely is it? A common approach is to assign each asset a rating (for example 1 to 3) for C, I and A. A public marketing brochure may be low C, medium I, low A. A payroll database may be high C, high I, medium A. An e-commerce website may be low C, high I, high A.
Step 4: Risk treatment (clause 6.1.3 and 8.3). Controls are selected to reduce risks to acceptable levels. The Statement of Applicability (SoA) lists necessary controls, justification for inclusion and exclusion, and implementation status. Justifications typically refer back to CIA risks.
Step 5: Monitoring and improvement (clauses 9 and 10). Metrics, internal audits, management reviews and incident analysis check whether CIA is effectively preserved. Incidents are classified by the property affected.
Balancing the Triad
The three properties often pull against each other. Strong encryption and strict access control improve confidentiality but may reduce availability if keys are lost or users are locked out. Multiple redundant copies improve availability but create more places where confidentiality can be breached and integrity can drift. A mature ISMS balances CIA according to business needs and risk appetite rather than maximizing one property at the expense of the others. Auditors look for evidence that these trade-offs were consciously considered in the risk assessment.
Mapping Common Scenarios to CIA
Stolen unencrypted laptop with client files: Confidentiality.
Employee changes bank account details in supplier records without authorization: Integrity.
DDoS attack takes the online portal offline: Availability.
Ransomware encrypts file servers: primarily Availability (and Integrity, since data is altered); if data is also exfiltrated, Confidentiality too.
Email sent to the wrong recipient: Confidentiality.
Spreadsheet formula error produces wrong financial report: Integrity.
Backups exist but have never been restore-tested and fail when needed: Availability (and possibly Integrity of recovered data).
Power failure in the data centre with no UPS: Availability.
Developer pushes untested code directly to production: Integrity (and potentially Availability).
Hashing a file to verify it has not changed: an Integrity control.
Encrypting data in transit: primarily a Confidentiality control (authenticated encryption also supports integrity).
The Auditor's Perspective
As a Lead Auditor, you use CIA to:
- Verify that the risk assessment methodology explicitly considers loss of C, I and A (clause 6.1.2 c) 1)). Absence of this is a clear nonconformity.
- Check that asset or information classifications reflect real business impact and are applied consistently.
- Test whether controls in the SoA actually address the CIA risks identified, and whether excluded controls are properly justified.
- Sample evidence: access reviews (C), change records and approvals (I), backup and restore test logs (A), business continuity tests (A), incident records categorized by property.
- Grade findings: a missing control that leaves highly confidential data exposed is more serious than a minor documentation gap. Link every finding to a requirement and, where useful, to the CIA impact so auditees understand why it matters.
- Write clear nonconformity statements: requirement, evidence, and the gap. For example: 'Clause 6.1.2 c) 1) requires identification of risks associated with the loss of confidentiality, integrity and availability. The risk register reviewed (version 3, dated March) identifies only confidentiality risks; no integrity or availability risks were recorded for the payment system.'
Exam Tips: Answering Questions on Confidentiality, Integrity and Availability
1. Memorize the official ISO/IEC 27000 definitions. Confidentiality: not disclosed to unauthorized individuals, entities or processes. Integrity: accuracy and completeness. Availability: accessible and usable on demand by an authorized entity. Exams often test the exact wording, and distractors use near-miss definitions (for example, describing reliability or authenticity as integrity).
2. Look for trigger words. Disclosure, leak, unauthorized access, viewed, eavesdropping, privacy point to Confidentiality. Altered, modified, corrupted, tampered, accurate, complete, wrong, error point to Integrity. Outage, downtime, unavailable, delay, deleted, cannot access, disruption, DoS point to Availability.
3. Identify the primary property first. Many scenarios affect more than one property. If the question asks for the property most affected or primarily compromised, choose the one that is the direct, immediate consequence. A DDoS attack does not disclose or change data; it is Availability. A lost encrypted laptop is mostly an Availability issue for that device, while a lost unencrypted laptop is a Confidentiality issue.
4. Match controls to properties. Encryption, access control, NDAs, classification, data masking: Confidentiality. Hashing, digital signatures, change management, segregation of duties, input validation, logging: Integrity. Backups, redundancy, UPS, capacity management, business continuity: Availability. Be ready to explain why a control supports more than one property.
5. Remember the clause reference. The direct ISO/IEC 27001 link to CIA is clause 6.1.2 c) 1). In auditor-style questions, citing this clause shows precise knowledge and strengthens your answer when a risk assessment ignores one of the properties.
6. Do not confuse related terms. Authenticity (genuine source), non-repudiation (cannot deny an action), accountability and reliability are related to, but not the same as, the CIA triad. If the answer options include both 'Integrity' and 'Authenticity', read carefully: proving who sent a message is authenticity or non-repudiation; proving the message was not changed is integrity.
7. In scenario and essay questions, structure your answer. State the property affected, explain why using the definition, identify the relevant clause or Annex A control, describe the audit evidence you would seek, and if asked, classify the finding (major or minor nonconformity, or opportunity for improvement) with justification.
8. Think like an auditor, not an implementer. Lead Auditor exams reward answers that focus on verifying conformity with evidence, not designing the perfect technical solution. The question is usually 'Does the organization meet the requirement and how do you know?' rather than 'What firewall should they buy?'
9. Consider balance and risk appetite. If a question asks whether an organization must apply the strongest possible confidentiality controls everywhere, the answer is no: ISO 27001 is risk-based. Controls should be proportionate to the CIA impact determined in the risk assessment.
10. Watch for ransomware and backup traps. Ransomware is commonly tested. The classic answer is Availability (data inaccessible), but recognise that modern double-extortion attacks also breach Confidentiality. Backups mainly protect Availability, but untested or unprotected backups introduce Integrity and Confidentiality risks.
11. Use the ISO/IEC 27002 attributes. If you are allowed reference material, ISO/IEC 27002:2022 tags each control with its information security properties. This is a quick, authoritative way to confirm which CIA element a control supports.
12. Eliminate absolute answers. Options with 'always', 'never', or 'only' (for example 'encryption only protects confidentiality') are often wrong, because many controls support multiple properties.
Practice Questions
Q1. An attacker intercepts and reads unencrypted emails between a company and its lawyer. Which property is primarily compromised?
Answer: Confidentiality. The information was disclosed to an unauthorized party but was not changed or made unavailable.
Q2. A finance clerk without approval alters a vendor's bank details, causing payments to go to a fraudulent account. Which property is compromised and which control would most directly prevent it?
Answer: Integrity. Segregation of duties (Annex A 5.3) and approval workflows with access restriction (8.3) and logging (8.15) would prevent or detect it.
Q3. During an audit you find that the risk register lists threats of data disclosure but no risks related to system outages or data corruption. What is your finding?
Answer: A nonconformity against clause 6.1.2 c) 1), which requires identification of risks associated with the loss of confidentiality, integrity and availability. Grade based on the extent: if the risk process systematically ignores I and A, this is likely a major nonconformity because the risk assessment process fails to achieve its intended outcome.
Q4. Which of the following best defines availability according to ISO/IEC 27000? a) Systems operate without errors; b) Information is accessible and usable on demand by an authorized entity; c) Information is accurate and complete; d) Information is available to anyone who requests it.
Answer: b. Option a describes reliability, c describes integrity, and d ignores authorization.
Q5. An organization uses digital signatures on contracts. Which properties does this mainly support?
Answer: Integrity (the document has not been altered) plus authenticity and non-repudiation (the signer is verified and cannot deny signing). It does not, by itself, provide confidentiality.
Summary
The CIA triad is the heart of ISO/IEC 27001. Confidentiality keeps information away from unauthorized eyes, integrity keeps it accurate and complete, and availability ensures authorized users can access it when needed. The standard requires risks to all three to be identified (clause 6.1.2 c) 1)), treated through proportionate controls documented in the SoA, and monitored for effectiveness. As a Lead Auditor candidate, master the official definitions, link scenarios and controls to the correct property, cite the right clause, and always back your conclusions with evidence. Doing so will help you answer exam questions confidently and audit real organizations effectively.
Unlock Premium Access
ISO/IEC 27001 Lead Auditor
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 3041 Superior-grade ISO/IEC 27001 Lead Auditor practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- ISO 27001 LA: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!