The CIA Strikes Back: Redefining Confidentiality, Integrity and Availability in Security



Full text

Journal of Information System Security
Volume 10, Number 3 (2014)
Pages 2145
ISSN 1551-0123
Spyridon Samonas — Virginia Commonwealth University, USA
David Coss — Virginia State University, USA
Information Institute Publishing, Washington DC, USA




This paper reviews the history of the CIA (Confidentiality, Integrity and Availability)triad from the perspectives of information security practitioners and scholars.Whilst the former have trusted the technical orientation of the triad as a uniquepoint of reference in information security, the latter have questioned the triad’scapacity of addressing the breadth of socio-technical issues that have emerged insecurity since the 2000s. Through a revisiting of the key tenets of the triad, thepaper reconciles these two, seemingly fragmented, approaches. The main argumentis that the CIA triad will continue to assume a major role in information securitypractice. However, this is not due to the fact that practitioners have discarded, orrejected the enhancements that socio-technical security scholars have proposedover the years; rather, it is because these enhancements can be accommodated by abroader re-conceptualization of the original CIA triad. The paper concludes withpotential areas for future research.




Confidentiality, Integrity, Availability, Socio-technical security




