Assets and the CIA Triad
What you own, and the three promises security makes about it.
- An asset is anything of value: devices, data, accounts, applications, and reputation.
- Confidentiality: only authorized people can read it.
- Integrity: it stays accurate and unaltered except by those allowed to change it.
- Availability: it is there and working when legitimate users need it.
Picture your organization as a city of houses. Every house holds something: family photos, jewelry, the deed to the property. In your digital city, the houses are servers, laptops, and cloud accounts — and the valuables inside are data, credentials, and the trust your customers place in you. These are your assets, and the first rule of defense is simple: you cannot protect what you have not counted.
Security makes three promises about every asset, known as the CIA triad:
- Confidentiality — only the right people can look inside the house. A stolen customer database is a confidentiality failure.
- Integrity — nobody rearranges the furniture without permission. An attacker silently changing payroll account numbers is an integrity failure.
- Availability — the family can get into their own house. Ransomware that locks every door is an availability failure.
Every attack you will ever study violates at least one of these three promises, and every defense you will ever deploy exists to keep one of them. When you hear about a breach in the news, train yourself to ask: which promise was broken? That single habit turns headlines into lessons.
The Vijilan SOC frames every alert the same way: what asset is involved, and which of the three promises is at risk? Triage starts with value, not with technology.
A disgruntled employee deletes the only copy of a project folder before quitting. Which CIA promise was broken?
