Most security goals map to Confidentiality, Integrity, and Availability—plus privacy and safety extensions in modern products.
Definitions
- Confidentiality — only authorized parties read data (encryption, access control)
- Integrity — data and systems are accurate and unaltered (hashing, signatures, audit logs)
- Availability — systems work when needed (redundancy, DDoS mitigation, backups)
Trade-offs
Strict confidentiality (heavy encryption) can hurt availability (latency). Security balances business needs—not maximum lockdown everywhere.
Important interview questions and answers
- Q: Which triad for HTTPS?
A: Confidentiality + integrity in transit; availability is separate uptime work. - Q: Ransomware hits which legs?
A: Often availability (encrypt files) and confidentiality (exfiltration).
Self-check
- What does each CIA letter mean?
- Give one control for confidentiality.
Tip: Label each control you ship as C, I, or A—clarifies design reviews.
Interview prep
- Confidentiality?
Limit who can read data.
- Availability?
Systems accessible when needed.