ISC2-CC - Security Principles - Section 1.1

Understand the security concepts of information assurance, including confidentiality, integrity, availability, authentication, non-repudiation, and privacy.

Define the CIA triad - confidentiality, integrity, and availability - as the three pillars that every security control ultimately serves, and recognise authentication, non-repudiation, and privacy as the supporting assurances. Distinguish the methods of authentication, including single-factor and multi-factor authentication (MFA), and identify which pillar a given control or breach affects.

CIA triadConfidentialityIntegrityAvailabilityMulti-factor authentication

Practice question for this objective

Free sampleSecurity Principleseasy

A training officer at a clinic explains that one member of the CIA triad is about making sure information is not disclosed to people or systems that have no authorisation to see it. Which member of the triad does this description define?

  • AConfidentiality, because it limits disclosure of information to those parties that have been properly authorised to access it. Correct
  • BIntegrity, because it keeps stored records accurate and unaltered by anyone who lacks the proper authorisation to change them.
  • CAvailability, because it keeps information reachable so that authorised users can obtain it whenever they legitimately need it.
  • DNon-repudiation, because it prevents a party from denying that it accessed or disclosed a given piece of information.
Confidentiality is the CIA triad property that prevents disclosure of information to unauthorised people or systems. Confidentiality restricts who can view data, so its purpose is to keep information from being disclosed to parties that lack authorisation, which distinguishes it from integrity and availability.

Why A is correct: Confidentiality is the triad property that prevents disclosure of information to unauthorised people or systems, which is exactly what the description states.

Why B is wrong: Integrity is tempting because unauthorised change is also a concern, but integrity concerns accuracy and prevention of alteration, not the prevention of disclosure that the description names.

Why C is wrong: Availability sounds relevant because it also involves authorised users, but it addresses timely access to data rather than stopping unauthorised parties from seeing it.

Why D is wrong: Non-repudiation is tempting through its link to accountability, but it proves that an action occurred rather than preventing disclosure to unauthorised parties.

See more ISC2-CC practice questions with worked answers.

More in this domain

Back to all Security Principles objectives, or the ISC2-CC cert hub.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.