Skip to main content
Category: Security & Breach Notification

Confidentiality, Integrity, Availability and Resilience

Also known as: CIA, CIA triad, Confidentiality, Integrity and Availability, CIA triad and resilience
Simply put

This term refers to the core objectives organizations aim to achieve when protecting information: keeping data private (confidentiality), keeping it accurate and unaltered (integrity), and keeping it accessible when needed (availability). Resilience is the related capacity to maintain or restore these properties after a disruption or incident. Together they provide a widely used framework for designing security policies and procedures.

Formal definition

The traditional CIA triad comprises three pillars of information security: confidentiality (preserving authorized restrictions on information access and disclosure, including means for protecting personal privacy and proprietary information), integrity (guarding against improper information modification or destruction), and availability (ensuring timely and reliable access to and use of information). Resilience extends this model to the ability to maintain and restore these properties in the face of adverse events. Note that the specific phrasing 'confidentiality, integrity, availability and resilience' commonly appears in the GDPR's security-of-processing provisions as a framing of appropriate technical and organizational measures; that regulatory usage is distinct from, though conceptually aligned with, the general information-security CIA triad described in the evidence here, and readers should verify the exact statutory wording against the current official text.

Why it matters

Confidentiality, integrity, and availability form the conceptual foundation of information security, giving organizations a structured way to think about what they are protecting and why. Rather than treating security as an undifferentiated goal, the triad separates distinct objectives: keeping data from unauthorized access or disclosure, guarding against improper modification or destruction, and ensuring information remains accessible when it is needed. This model has long served as a foundation for establishing security procedures and policies, and it helps teams reason about trade-offs when a single control cannot satisfy every objective simultaneously.

For data privacy work specifically, the phrasing 'confidentiality, integrity, availability and resilience' carries particular weight because it commonly appears in the GDPR's security-of-processing provisions as a framing of appropriate technical and organizational measures. Although that regulatory usage is distinct from the general information-security CIA triad, the two are conceptually aligned, and controllers and processors typically draw on the triad when designing and documenting the security measures they must implement. Readers should verify the exact statutory wording against the current official text, as the precise language and the article in which it appears should not be assumed from a general description.

The pillars are also interdependent, which is why the framework matters in practice rather than as an abstraction. As commentary in the evidence notes, confidentiality means little if data is not available, and integrity is irrelevant if unauthorized users can manipulate records. Treating the objectives together, and adding resilience as the capacity to maintain or restore these properties after a disruption, gives organizations a more complete basis for risk-based security decisions. The appropriateness of any specific set of measures remains context and risk dependent and should be assessed accordingly.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance teams rely on the triad, extended with resilience, as a vocabulary for assessing and documenting the security measures required under GDPR's security-of-processing obligations. It helps them frame conversations with security teams and evidence that appropriate technical and organizational measures have been considered, though the appropriateness of any given measure remains a risk-based assessment and the exact statutory language should be verified.
Security engineers and architects
Engineers use the triad as a guide for establishing security procedures and policies and for selecting controls that map to confidentiality, integrity, and availability objectives, with resilience addressing recovery after disruption. Because the objectives can be interdependent, engineers typically weigh trade-offs among them rather than optimizing for one in isolation.
Privacy and technology lawyers
Lawyers advising on data protection encounter the phrase 'confidentiality, integrity, availability and resilience' in the context of GDPR security requirements. They should treat the regulatory usage as distinct from, though aligned with, the general information-security triad, and should confirm the precise wording, article reference, and any national derogations against the current official text before relying on it.
Controllers and processors
Both controllers and processors have obligations relating to the security of processing, and the triad plus resilience offers a shared framework for defining and allocating security measures, including in Data Processing Agreements under Article 28. The specific measures that are appropriate depend on context and risk and should be assessed accordingly.

Inside CIA

Confidentiality
The property that personal data is not disclosed to, or accessed by, unauthorised persons, entities, or processes. In the GDPR context this is generally reflected in the security obligation under Article 32, which requires appropriate technical and organisational measures. Confidentiality is one component of security of processing and does not, on its own, satisfy the whole obligation.
Integrity
The property that personal data remains accurate and complete and is not altered in an unauthorised or accidental manner. Integrity in the security sense (protecting data against unauthorised modification) is related to but distinct from the accuracy principle in Article 5(1)(d), which concerns keeping data correct and up to date as a data quality matter.
Availability
The property that personal data and the systems processing it can be accessed and used when required by authorised parties. Article 32 refers, among other things, to the ability to ensure ongoing availability of processing systems and services.
Resilience
The ability of processing systems and services to withstand, and continue operating despite, adverse events, and to maintain the other properties over time. Article 32 references ongoing resilience of processing systems and services alongside the ability to restore availability and access in a timely manner after an incident.
Restoration and testing dimension
Article 32 also contemplates the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident, and a process for regularly testing, assessing, and evaluating the effectiveness of the measures. These operational elements support, and are typically assessed together with, confidentiality, integrity, availability, and resilience.

Common questions

Answers to the questions practitioners most commonly ask about CIA.

Are confidentiality, integrity, availability and resilience only about keeping data secret and preventing breaches?
No. While confidentiality does concern protecting personal data against unauthorised access or disclosure, it is only one of the properties named in this context. Integrity concerns ensuring data is not improperly altered, availability concerns ensuring authorised access when needed, and resilience concerns the ability of systems and services to recover from and withstand incidents. Treating the concept as secrecy alone typically understates the obligations, which extend to accuracy, accessibility, and the ongoing robustness of processing systems and services.
Does achieving confidentiality, integrity, availability and resilience mean an organisation is fully compliant with its security obligations?
Not necessarily. These properties describe objectives that security measures are generally intended to support, but security under the GDPR is framed as appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing. Compliance is context and risk dependent, so demonstrating these properties is part of an assessment rather than a fixed endpoint that guarantees a fully compliant position.
How can an organisation demonstrate that measures for these properties are appropriate to the risk?
In most cases organisations document a risk assessment linking identified risks to the personal data and processing against the technical and organisational measures selected. This typically includes recording the reasoning for measures addressing confidentiality, integrity, availability and resilience, and revisiting that reasoning as risks, technologies and threats change. The appropriateness of measures is judged against the state of the art and the specific processing, so the demonstration should reference those factors rather than a generic checklist.
What kinds of measures typically support the resilience element specifically?
Resilience generally relates to a system's or service's ability to continue operating and to recover from incidents. Measures commonly considered in this area include redundancy, backup and restoration arrangements, tested continuity and recovery processes, and the ability to restore availability and access to personal data in a timely manner following an incident. The suitable combination depends on the processing and should be assessed rather than assumed, and testing regimes are typically part of showing that resilience is maintained in practice.
How should integrity be addressed when implementing safeguards?
Integrity typically concerns protecting personal data against unauthorised or accidental alteration and ensuring it remains accurate and complete for its purpose. Implementation measures often include access controls limiting who can modify data, logging and audit trails, validation controls, and mechanisms to detect unauthorised changes. Because integrity interacts with accuracy expectations, organisations generally consider both technical controls and organisational processes, and the appropriate balance is subject to assessment against the specific processing risks.
How often should measures for these properties be reviewed and tested?
There is no single prescribed interval, so review frequency is generally determined by the risk and the pace of change in the relevant systems, threats and technologies. A common approach is to establish a process for regularly testing, assessing and evaluating the effectiveness of the measures, and to trigger additional reviews after significant incidents or material changes to processing. Because the appropriate cadence is context dependent, organisations should document their chosen approach and verify it against current official guidance rather than relying on a fixed timetable.

Common misconceptions

Achieving confidentiality (for example, through encryption) means the Article 32 security obligation is met.
Confidentiality is only one aspect. Article 32 generally requires measures appropriate to the risk that also address integrity, availability, and resilience, along with the ability to restore access after an incident and to regularly test the measures. What is appropriate is assessed by reference to the state of the art, costs, and the nature, scope, context, and purposes of processing and the risks involved, so the position is context and risk dependent.
The integrity element of security is the same as the accuracy principle in Article 5.
They are related but distinct. Integrity as a security property concerns protecting data against unauthorised or accidental alteration, whereas the accuracy principle under Article 5(1)(d) is a data quality obligation to keep personal data correct and, where necessary, up to date. A given control may support both, but satisfying one does not automatically satisfy the other.
There is a fixed, universally compliant set of measures that guarantees these properties.
The GDPR takes a risk-based approach rather than prescribing specific controls, so no measure can be described as always compliant. Appropriateness is judged against the risk to individuals and other factors, and expectations evolve with the state of the art and regulatory guidance. Practitioners should verify current requirements against the official text and applicable guidance.

Best practices

Address all four properties, confidentiality, integrity, availability, and resilience, together rather than treating security as encryption alone, and document how each is supported by the measures in place.
Carry out and record a risk-based assessment that ties the chosen technical and organisational measures to the nature, scope, context, and purposes of processing and the risks to individuals, consistent with the appropriateness standard in Article 32.
Implement and document processes to restore the availability of and access to personal data in a timely manner after a physical or technical incident, and test those recovery capabilities.
Establish a process for regularly testing, assessing, and evaluating the effectiveness of the measures, and update them as risks, systems, and the state of the art change.
Distinguish security integrity controls from the Article 5 accuracy obligation in your documentation so that both data-protection and data-quality requirements are addressed.
Review measures against current official text and applicable regulatory guidance periodically, since expectations for appropriate security evolve and can vary by context.