Confidentiality, Integrity, Availability and Resilience
This term refers to the core objectives organizations aim to achieve when protecting information: keeping data private (confidentiality), keeping it accurate and unaltered (integrity), and keeping it accessible when needed (availability). Resilience is the related capacity to maintain or restore these properties after a disruption or incident. Together they provide a widely used framework for designing security policies and procedures.
The traditional CIA triad comprises three pillars of information security: confidentiality (preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information), integrity (guarding against improper information modification or destruction), and availability (ensuring timely and reliable access to and use of information). Resilience extends this model to the ability to maintain and restore these properties in the face of adverse events. Note that the specific phrasing 'confidentiality, integrity, availability and resilience' commonly appears in the GDPR's security-of-processing provisions as a framing of appropriate technical and organizational measures; that regulatory usage is distinct from, though conceptually aligned with, the general information-security CIA triad described in the evidence here, and readers should verify the exact statutory wording against the current official text.
Why it matters
Confidentiality, integrity, and availability form the conceptual foundation of information security, giving organizations a structured way to think about what they are protecting and why. Rather than treating security as an undifferentiated goal, the triad separates distinct objectives: keeping data from unauthorized access or disclosure, guarding against improper modification or destruction, and ensuring information remains accessible when it is needed. This model has long served as a foundation for establishing security procedures and policies, and it helps teams reason about trade-offs when a single control cannot satisfy every objective simultaneously.
For data privacy work specifically, the phrasing 'confidentiality, integrity, availability and resilience' carries particular weight because it commonly appears in the GDPR's security-of-processing provisions as a framing of appropriate technical and organizational measures. Although that regulatory usage is distinct from the general information-security CIA triad, the two are conceptually aligned, and controllers and processors typically draw on the triad when designing and documenting the security measures they must implement. Readers should verify the exact statutory wording against the current official text, as the precise language and the article in which it appears should not be assumed from a general description.
The pillars are also interdependent, which is why the framework matters in practice rather than as an abstraction. As commentary in the evidence notes, confidentiality means little if data is not available, and integrity is irrelevant if unauthorized users can manipulate records. Treating the objectives together, and adding resilience as the capacity to maintain or restore these properties after a disruption, gives organizations a more complete basis for risk-based security decisions. The appropriateness of any specific set of measures remains context and risk dependent and should be assessed accordingly.
Who it's relevant to
Inside CIA
Common questions
Answers to the questions practitioners most commonly ask about CIA.