Guide (Overly Informative)
A
R
U
LA
C
O
D
, CIA Triad - ANS Confidentiality, Integrity, Availability
Parkerian hexad - ANS Where the CIA triad consists of confidentiality, integrity, and
A
availability, the Parkerian hexad consists of these three principles, as well as possession or
control, authenticity, and utility
R
Confidentiality - ANS Refers to our ability to protect our data from those who are not
authorized to view it.
Confidentiality can be compromised by the loss of a laptop containing data, a person looking
U
over our shoulder while we type a password, an e-mail attachment being sent to the wrong
person, an attacker penetrating our systems, or similar issues.
LA
Integrity - ANS Refers to the ability to prevent our data from being changed in an
unauthorized or undesirable manner. This could mean the unauthorized change or deletion of
our data or portions of our data, or it could mean an authorized, but undesirable, change or
deletion of our data. To maintain integrity, we not only need to have the means to prevent
unauthorized changes to our data but also need the ability to reverse authorized changes that
need to be undone.
C
Availability - ANS refers to the ability to access our data when we need it. Loss of
availability can refer to a wide variety of breaks anywhere in the chain that allows us access to
our data. Such issues can result from power loss, operating system or application problems,
O
network attacks, compromise of a system, or other problems. When such issues are caused by
an outside party, such as an attacker, they are commonly referred to as a denial of service
(DoS) attack.
D
Possession or Control - ANS Refers to the physical disposition of the media on which the
data is stored. This enables us, without involving other factors such as availability, to discuss our
loss of the data in its physical medium
An example is data store be on multiple devices and there could be numerous versions.
Authenticity - ANS Attribution as to the owner or creator of the data in question.
Authenticity can be enforced through the use of digital signatures.