The CIA triad (Confidentiality, Integrity, and Availability) is the three-part model that defines what security controls exist to protect. Confidentiality keeps information away from unauthorized eyes, integrity ensures data stays accurate and unaltered, and availability guarantees that authorized users can reach systems and data when they need them.
Every control you deploy supports at least one leg of the triad, and the legs often pull against each other. Heavy encryption and strict access rules strengthen confidentiality but can slow availability. A common mistake candidates make is treating the three goals as equally weighted in every situation. Priorities shift with the asset: a public marketing site leans on availability and integrity, while a database of medical records leans hard on confidentiality.
How is the CIA triad tested on the CISSP?
The CIA triad anchors Domain 1, Security and Risk Management, and it resurfaces everywhere else because each control maps back to one of the three goals. Exam questions often sketch a scenario and ask which principle a given threat or safeguard most affects, so read for the asset and the business priority. Review Domain 1: Security and Risk Management to see how the triad frames risk decisions.
Related control families are catalogued in NIST SP 800-53.