Confidentiality, Integrity and Availability (CIA) Are Not Principles of Information Security

The triad of Confidentiality, Integrity and Availability (CIA) is frequently described as the set of “fundamental principles” of information security. This characterization, although widespread in technical literature and educational materials, lacks conceptual precision.

This article argues that CIA constitutes a set of dimensions or functional goals rather than principles in the normative or explanatory sense. A more precise conceptual taxonomy is proposed, distinguishing between principles, dimensions, requirements, elements and objectives. The article also suggests several candidates for genuine information security principles that may provide a more coherent basis for teaching, system design and security management.

[Versión en Español]

Personal note: We may be living through the precise moment of the technological singularity, with artificial intelligence transforming everything, and I am worried about the use of a word. But what can you do? We need something to keep us busy in the meantime.

1. Introduction

In the field of information security (also called digital security), it is common to encounter statements claiming that its three “fundamental principles” are confidentiality, integrity and availability. This triad —known as CIA (Confidentiality, Integrity, Availability)— has become institutionalized in educational programs, international standards and training materials.

However, this classification involves a conceptual imprecision that deserves reconsideration: CIA does not constitute a set of principles in the strict sense, but rather a grouping of key dimensions of information.

This article critically examines this interpretation by analyzing the concept of principle from a philosophical perspective and proposing a conceptual taxonomy that clarifies the place occupied by CIA within the theoretical architecture of information security. On the basis of this review, an alternative proposal is presented that includes some candidates for genuine principles of security, with explanatory and prescriptive capacity.

Appendices 1 and 2 cite sources that refer to CIA as principles, in Spanish and English respectively.

2. What Is a Principle?

A principle is a general law, a guiding rule, or a systematic relationship between elements. According to Ferrater Mora’s Dictionary of Philosophy (1994), a principle is “a proposition or statement considered to be a fundamental starting point of a science, doctrine or system.”

A principle may be humorous, ironic, full of exceptions or simply wrong, but it is never merely an isolated concept. It always points to a relationship between at least two ideas.

  • In ethics, the principle of symmetry establishes that a rule should apply independently of the position one occupies in a conflict.
  • In economics, the principle of scarcity states that only what is scarce has economic value.
  • In hydraulics, Pascal’s principle explains how pressure is transmitted in fluids.
  • In medicine, the principle that “prevention is better than cure” is well known, as is the principle of non nocere (“above all, do no harm”). We may also warn that “Anyone who goes into the operating room is taking a risk.”
  • In plumbing, we might say that “water flows downhill,” “the customer is always right,” or “every customer has a ‘while-you’re-here’” (“while you’re here, could you have a look at this other thing?”).
  • Every waiter knows that “it is better to have too much than too little.”

 

Principles, therefore, are guiding ideas that define the framework for action or understanding within a discipline. They are not merely labels or lists of desirable properties.

It is worth emphasizing that the intention here is not to argue which principles are valid or correct. This text discusses only what type of statement can be classified as a “principle” within a discipline and, in particular, within digital security. A principle may have multiple exceptions, may become obsolete, or may simply be wrong.

3. CIA Are Not Principles

Let us now examine why CIA does not satisfy the conditions for being called principles:

  • Confidentiality is an objective: only authorized persons should have access to certain information.
  • Integrity is a desired condition: information should not be altered or manipulated without authorization.
  • Availability is an operational property: information should be accessible when it is needed.

None of these elements establishes a general relationship between variables, prescribes a design rule, or guides a strategy in causal or normative terms. Instead, they function as key dimensions of the information to be protected.

4. A Conceptual Taxonomy for Security

To overcome this confusion, a more precise taxonomy is proposed:

  • Principles: guiding ideas with general normative or explanatory value. E.g., “security has a cost.”
  • Dimensions: key aspects of information. E.g., confidentiality, integrity, availability.
  • Requirements: conditions necessary to achieve the objectives. E.g., authentication, traceability.
  • Elements: practices or technical components. E.g., inventory, firewall, training, updates, backups.
  • Objectives: functional goals. E.g., protecting sensitive data, ensuring operational continuity.

5. Proposal: Genuine Principles of Information Security

The following is a preliminary proposal for genuine principles of information security. Some of these principles may be debatable, and it is plausible to argue that they do not hold up empirically or conceptually. However, the purpose of this article is not to establish which principles of information security are correct, but to establish what type of statement can fit the definition of a principle.

  1. Principle of cost: Every security measure has a cost, whether economic, cognitive or temporal.
  2. Principle of impossibility: There is no completely secure system; all protection is always limited, relative and contextual.
  3. Principle of proportionality: The more critical the information or system, the higher its level of security should be.
  4. Principle of redundancy: Security is strengthened through redundant layers of control and defense.
  5. Principle of asymmetry: It is easier to attack than to defend; it is easier to destroy than to build. Entropy favours the attacker.
  6. Principle of inconvenience: The greater the security, the greater the inconvenience or friction for the user.
  7. Principle of knowledge of evil: Understanding attack vectors is a condition for preventing them. To prevent harmful actions, we must understand in detail how they are carried out.
  8. Principle of least privilege: Every user or process should have the minimum permissions necessary to perform its function.
  9. Principle of suspicion: If something seems too good to be true, it probably is not true (as a defense against phishing).
  10. Principle of resilience: In digital security, the idea exactly contrary to the popular saying that “prevention is better than cure” is gaining increasing strength. Instead of insisting on trying to prevent incidents, it is better to devote a large proportion of our efforts to minimizing their impact when they occur.

These principles make it possible to build a more robust and useful theoretical framework to guide the design of cybersecurity systems and policies.

6. Conclusion

The terminological confusion between principles and dimensions in the field of information security is not a minor detail. A mature discipline requires a precise conceptual architecture, based on well-defined categories that allow the critical evaluation of its foundations and the formulation of coherent intervention strategies.

Repositioning the CIA triad in its proper place —as dimensions or objectives— and replacing the term “principles” with genuinely normative criteria not only improves conceptual precision, but also strengthens the teaching, analysis and practice of security.

References

  • Ferrater Mora, J. (1994). Diccionario de Filosofía (Vol. IV). Madrid: Alianza Editorial.
  • ISO/IEC 27001:2022. Information Security, Cybersecurity and Privacy Protection — Information Security Management Systems — Requirements.
  • National Institute of Standards and Technology (NIST). (1995). An Introduction to Computer Security: The NIST Handbook (SP 800-12). https://csrc.nist.gov/publications
  • Auditool. (n.d.). Principios básicos de seguridad de la información: Confidencialidad, Integridad y Disponibilidad (CIA). https://www.auditool.org
  • DataSunrise. (n.d.). Confidencialidad, Integridad, Disponibilidad: Ejemplos clave. https://www.datasunrise.com/es/
  • ISTQBHUB. (n.d.). Los 4 principios de la seguridad informática. https://istqbhub.io
  • Infosecurity Europe. (2024, July 9). What are the 3 principles of information security? https://www.infosecurityeurope.com
  • SailPoint. (2025, January). CIA triad: Confidentiality, integrity, and availability. https://www.sailpoint.com
  • SecurityScorecard. (2025, May). What is the CIA Triad? Definition, Importance, & Examples. https://securityscorecard.com
  • Splunk. (2024, November). What’s the CIA Triad? Confidentiality, Integrity, & Availability, Explained. https://www.splunk.com

Appendix 1: Spanish-Language References That Cite CIA (Confidentiality, Integrity and Availability) as “Principles”

  1. Auditool. (n.d.). Principios básicos de seguridad de la información: Confidencialidad, Integridad y Disponibilidad (CIA). Retrieved from https://www.auditool.org/blog/auditoria-de-ti/principios-basicos-de-seguridad-de-la-informacion-confidencialidad-integridad-y-disponibilidad-cia. The title itself is: “Basic Principles of Information Security: Confidentiality, Integrity and Availability (CIA).”
  2. DataSunrise. (n.d.). Confidencialidad, Integridad, Disponibilidad: Ejemplos clave. Retrieved from https://www.datasunrise.com/es/centro-de-conocimiento/ejemplos-de-confidencialidad-integridad-disponibilidad. “The CIA triad, composed of confidentiality, integrity and availability, is a fundamental framework in information security. These principles guide organizations in protecting sensitive data, ensuring that they are secure, accurate and accessible only to authorized persons when necessary.”
  3. ISTQBHUB. (n.d.). Los 4 principios de la seguridad informática. Retrieved from https://istqbhub.io/blog/seguridad/los-4-principios-de-la-seguridad-informatica/. “The CIA triad, composed of confidentiality, integrity and availability, is a fundamental framework in information security. These principles guide organizations in protecting sensitive data, ensuring that they are secure, accurate and accessible only to authorized persons when necessary.”

Appendix 2: English-Language References That Cite CIA (Confidentiality, Integrity and Availability) as “Principles”

  1. Infosecurity Europe. (2024, July 9). What are the 3 principles of information security? Retrieved from https://www.infosecurityeurope.com/en-gb/blog/guides-checklists/principles-of-information-security.htm.
  2. SailPoint. (2025, January). CIA triad: Confidentiality, integrity, and availability. Retrieved from https://www.sailpoint.com/identity-library/cia-triad.
  3. SecurityScorecard. (2025, May). What is the CIA Triad? Definition, Importance, & Examples. Retrieved from https://securityscorecard.com/blog/what-is-the-cia-triad/.
  4. Splunk. (2024, November). What’s the CIA Triad? Confidentiality, Integrity, & Availability, Explained. Retrieved from https://www.splunk.com/en_us/blog/learn/cia-triad-confidentiality-integrity-availability.html.

 

Posted by Manu Herrán

Founder at Sentience Research. Chief Advisor at The Far Out Initiative,

Leave a Reply

Your email address will not be published. Required fields are marked *