Chapter One
What Security Means: Confidentiality, Integrity and Availability
Syllabus topic Module 1, "Introduction: Security Trends, The OSI Security Architecture, Security Attacks, Security Services, Security Mechanisms"
In one line
Security means that information and the systems holding it keep doing exactly what their owner intended, and nothing else. Three properties carry that promise: nobody who should not see the data sees it, nobody who should not change the data changes it, and the people who need the data can get it when they need it.
In the wording a student can write in an examination: information security is the protection of information and information systems from unauthorised access, use, disclosure, disruption, modification or destruction, in order to preserve confidentiality, integrity and availability. These three are called the CIA triad, and they are the objectives against which every control in this subject is judged.
Why the subject begins here
Almost nobody attacks a computer for its own sake. They attack it because of what the information inside it can be made to do: a mark that can be raised, a payment that can be redirected, a message that can be read. So the useful question is never "is this system secure", which has no answer, but "which of the three properties does this control protect, and against whom". A student who can name the property under attack can answer half of this paper, because MU's whole Module 1 is built on that vocabulary.
The three properties also give you a way to talk about a loss. When a college result server is defaced, nothing was stolen and nothing was read, so it is not a loss of confidentiality; the marks were altered, so it is a loss of integrity. When the same server is knocked offline on the morning results are published, nothing was read and nothing was altered, so it is a loss of availability alone. Naming the loss correctly is the first step to choosing the control, and it is the thing examiners test.
The three properties, in the standard's own words
Confidentiality. FIPS 199, quoting the United States statute that defines it, is "Preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information". The standard then adds the plain version: "A loss of confidentiality is the unauthorized disclosure of information."
In plain English: only the people who are supposed to see it, see it. Your examination seat number is not confidential, because it is posted on a noticeboard. Your Aadhaar number is. Your marks are confidential from other students and not from you.
Integrity. FIPS 199: "Guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity". A loss of integrity is the unauthorised modification or destruction of information.
In plain English: the data is what it was, and nobody has quietly altered it. Notice that integrity is not about secrecy at all. A public examination timetable has no confidentiality whatever and enormous integrity requirements, because if somebody changes one date, a thousand students arrive on the wrong day.
What Security Means: Confidentiality, Integrity and Availability
Availability. FIPS 199: "Ensuring timely and reliable access to and use of information". A loss of availability is the disruption of access to or use of information or an information system.
In plain English: it works when you need it. This is the property people forget is part of security, and it is the one attacked most often in practice, because a denial of service attack needs no cleverness at all.
Two more that the standards add, and MU will expect you to know
Confidentiality, integrity and availability are the three the syllabus names, but the security literature adds two, and both appear later in this paper.
Authenticity. RFC 4949 defines authenticity as the property of being genuine and able to be verified and trusted. It is what a digital signature gives you: not only that the message was not altered, but that it came from the person it claims to have come from. It is the reason Module 1 spends five chapters on message authentication.
Accountability. The property that an entity's actions can be traced uniquely to that entity. It is what an audit log gives you, and without it there is no investigation after an incident and no non-repudiation. NIST SP 800-12 Rev. 1 treats both of these as objectives alongside the triad.
Worked example: why you cannot have all three at once
The system. A college publishes semester results on a web server. Three thousand students want them within an hour of publication. The Examination Section wants nobody to see them early and nobody to change them ever.
Step 1: strengthen confidentiality. Require every student to log in with a password, and post nothing publicly. Confidentiality improves. Availability falls, because three thousand simultaneous logins are far heavier than three thousand reads of one static page, and because several hundred students will have forgotten their password on the day.
Step 2: strengthen integrity. Require two officers of the Examination Section to approve every upload, and make the published file read only, signed, and impossible to correct without repeating the approval. Integrity improves. Availability falls again, because a genuine correction to one student's mark now takes two days.
Step 3: strengthen availability. Put the results file on a public content delivery network with no login, cached in fifty places so that no surge can slow it. Availability becomes excellent. Confidentiality is gone, because anyone with the address can read anyone's marks, and integrity is weaker, because there are now fifty copies and no single place to correct.
What Security Means: Confidentiality, Integrity and Availability
What the example shows. Every one of the three steps was a correct security decision, and every one made another property worse. Security is therefore not a quantity a system has more or less of; it is a set of deliberate trade-offs recorded against a stated requirement. When a question asks you to "design a secure system for X", it is asking which trade-off you chose and why, and an answer that promises all three is a weak answer.
Distinctions that carry marks
| Confidentiality | Integrity | Availability | |
|---|---|---|---|
| The promise | only the right people can read it | nobody has altered it | you can get to it when you need it |
| Attacked by | eavesdropping, theft of a database, a careless email | tampering, a virus, a wrong entry | a flood of traffic, a cut cable, ransomware |
| Broken means | disclosure | modification or destruction | disruption |
| Typical control | encryption, access control | hash, MAC, digital signature, backup | redundancy, capacity, rate limiting |
| Can you tell it happened | often not | yes, if you check | immediately, and loudly |
| Security | Privacy | |
|---|---|---|
| Asks | is the data protected from unauthorised access | should we hold this data at all, and for what |
| Decided by | the system's designers | law, and the person the data is about |
| In India | the technical controls in the Information Technology Act 2000 and its rules | the Digital Personal Data Protection Act 2023 |
| Relationship | you can have security without privacy, but not privacy without security |
What it does not mean
Security is not the same as cryptography. Cryptography is one mechanism, and it serves confidentiality, integrity and authenticity. It does nothing at all for availability, and a great deal of this paper's Module 2 is about controls with no cryptography in them: firewalls, intrusion detection, antivirus.
"Secure" is not a property a system has. It is always relative to a threat and a cost. A lock that resists a student with a hairpin does not resist a locksmith, and the honest statement is always "secure against whom, for how long, at what cost".
Integrity does not mean the data is correct. It means the data has not been altered since it was recorded. If the clerk typed 45 when the answer book said 54, integrity is perfect and the mark is wrong. Integrity protects the record, not the truth of what was recorded.
Availability failures are usually accidents. A power cut, a full disk and a wrong configuration take down more systems than attackers do, which is why availability sits inside security rather than beside it.
Quick revision
- Security: information and systems do what their owner intended, and nothing else.
- The CIA triad: confidentiality, integrity, availability.
- Confidentiality: preserving authorised restrictions on access and disclosure. Lost by disclosure.
- Integrity: guarding against improper modification or destruction. Lost by modification.
- Availability: timely and reliable access. Lost by disruption.
- Two more from the standards: authenticity (genuine and verifiable) and accountability (actions traceable to one entity).
- The three pull against each other. Strengthening one usually weakens another, and naming the trade-off is the answer.
- Integrity is about the record being unaltered, not about the record being true.
What Security Means: Confidentiality, Integrity and Availability
Test yourself
1. Define information security, and name the three properties it preserves. Information security is the protection of information and information systems from unauthorised access, use, disclosure, disruption, modification or destruction. The three properties are confidentiality (only authorised people can read the data), integrity (the data has not been improperly altered or destroyed) and availability (authorised users can reach the data when they need it).
2. A college's public examination timetable is altered so that one paper shows the wrong date. Which property was lost, and which was not? Integrity was lost: the data was modified without authority. Confidentiality was not lost, because the timetable was public and there was nothing to disclose. Availability was not lost either, because the page still answered.
3. Give one control for each of the three properties. Confidentiality: encrypt the data and require a login. Integrity: store a hash or a message authentication code with the record and check it before use. Availability: keep a second server and limit how many requests one address may make.
4. Why is it wrong to call a system "secure" without qualification? Because security is always relative to a threat, a time and a cost. A control that stops a curious classmate will not stop a funded attacker, so the meaningful claim names who the system resists and for how long.
5. A results server is put behind a login, and on results day it collapses under the load. Was that a security failure? Yes. Availability is one of the three properties, so a system that cannot be reached when it is needed has failed a security objective, even though the failure came from a control that was correctly protecting confidentiality. It is the trade-off in the worked example.
6. What do authenticity and accountability add to the triad? Authenticity is the property of being genuine and verifiable, so that a message can be shown to come from the party it claims to; a digital signature provides it. Accountability is the property that an action can be traced uniquely to the entity that performed it; an audit log provides it, and non-repudiation depends on it.
7. Distinguish security from privacy. Security asks whether data is protected from unauthorised access, and is decided by the people who build the system. Privacy asks whether the data should be collected and held at all, and for what purpose, and is decided by law and by the person the data concerns. Security is necessary for privacy but does not by itself produce it.