Discussion on:

11
Comments

Join the conversation!

Follow via:
RSS
Email Alert
0 Votes
+ -
The CIA Triad
apotheon 30th Jun 2008
The CIA Triad deals with three important factors of security:

1. Information Confidentiality

2. Information Integrity

3. Information Availability

What other factors do you consider important for developing a comprehensive security policy?
0 Votes
+ -
@ apotheon
xman_rbs@... 1st Jul 2008
I'd also like to suggest another A for Auditability.

This implies logging and analysis of those logs.

Being able to see who did what is a very important part of any overall security program.
...Information Accountability.

This covers InfoSec policies being enforceable, being widely known, and all stakeholders being properly educated.
0 Votes
+ -
Expanded CIA
mad2223 1st Jul 2008
With the rise in online transactions, as well as increased remote access and wireless connectivity, probably the addition of authentication and non-repudiation are good add-ons to the triad.
Authenticating the person into a system and making sure they are who they say they are seems like an obvious requirement. With the addition (expansion?) of multi-factor authentication methods throughout our everyday lives, this seems like an issue that needs to be taken very seriously. The days of using only a username/password combo are fading fast.
Non-repudiation deals with verifying that messages are sent by identifiable and verifiable senders - the sender cannot deny his message once he sends it.
0 Votes
+ -
CIAA
Digger Dave 1st Jul 2008
My 'periodic table' of security properties includes CIA and adds a 4th 'element' Accountability - defined as tracking the identity of persons or processes and their actions applied to the information asset. These 'elements' can be used to construct other 'molecules' such as non-repudiation.

The controls to prevent the compromise of the CIAvAc properties can be grouped into a number of categories, for example:
policy
technical (& physical) architecture
people
process
governance
0 Votes
+ -
excellent
apotheon 1st Jul 2008
I was hoping someone would come up with Accountability. It's a commonly overlooked, but very important, element of security policy.
0 Votes
+ -
Guns
BALTHOR 1st Jul 2008
One virus in the DSL and the whole thing goes down.
and I dont know why shocked
0 Votes
+ -
Don't forget the other big triad in information security - AAA, authentication, authorization and accounting.
0 Votes
+ -
I've got an article for you: The three elements of access control
0 Votes
+ -
CODE OF CIA
white house 23rd Apr 2010
number of code
Keyboard Shortcuts:
Prev
Next
Toggle
Join the conversation
Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]

Join the TechRepublic Community and join the conversation! Signing-up is free and quick, Do it now, we want to hear your opinion.