Confidentiality, integrity and availability: what security actually protects
Security protects three separate properties, not one attribute: each has its own impact.

Security protects information and information systems against the loss of three distinct properties: confidentiality (unauthorized disclosure), integrity (unauthorized modification or destruction) and availability (disruption of access or use). FIPS 199 carries the three objectives defined in 44 U.S.C. §3542 and gives every information type a separate potential impact — low, moderate or high — for each property on its own. The three are not one attribute and not three equal boxes to tick: a control that strengthens one property can cost another, so security is a set of trade-offs to be decided rather than an amount of something installed. NIST SP 800-30 Revision 1 defines information security risk precisely as risk that arises from the loss of confidentiality, integrity or availability — which is why these three words are the vocabulary every later governance decision (asset, threat, control, evidence) is written in.
The model: information, three properties, three losses
information and information systems
↓
three properties: confidentiality | integrity | availability
↓
three losses: unauthorized disclosure | unauthorized modification | disrupted access
↓
potential impact, one level per property: LOW | MODERATE | HIGH
↓
consequences for the organisation: limited | serious | severe or catastrophic
The three properties answer three different questions about the same information. Confidentiality asks who may see it; integrity asks whether it has been changed without authority; availability asks whether the people who need it can reach it. Each has its own defined failure — the loss — and the level of potential impact is assessed per property, not for “security” as a whole.
How the three properties become a decision
- Name the information type — a specific category of information such as personal, financial, medical or administrative information, defined by the organization or by an applicable law.
- For each of the three properties separately, ask what the potential impact of a loss would be.
- Record the answer as a level: LOW for a limited adverse effect, MODERATE for a serious one, HIGH for a severe or catastrophic one, on organizational operations, organizational assets or individuals.
- Write the result as a triple — the security category:
SC = {(confidentiality, impact), (integrity, impact), (availability, impact)}. In FIPS 199 the value may be LOW, MODERATE, HIGH or, for confidentiality of an information type, NOT APPLICABLE. - For a whole system, take the highest value found for each property across all information types it holds (the high-water mark). In NIST terminology, that categorization is the first step of the risk management process: it is what later decides which control baseline applies.
The properties pull in different directions
The levels are assessed separately, but the controls that deliver them interact. A control chosen to protect one property can spend another, which is what makes the model a trade-off rather than a checklist. That interaction is this sheet’s reading of the sources, not a rule they state.
| Property | The question it answers | A loss is | A control that strengthens it | What that control can cost |
|---|---|---|---|---|
| Confidentiality | Who may see this? | Unauthorized disclosure | Encryption, access control, least privilege | Slower or narrower access; lost keys can make data unrecoverable (availability) |
| Integrity | Has this changed without authority? | Unauthorized modification or destruction | Change control, signatures, hashes, audit logging | Extra steps delay legitimate change; logs consume time and storage |
| Availability | Can those who need it reach it? | Disruption of access or use | Redundancy, backups, capacity, failover | Duplication costs capacity and money; wider access can open the other two |
Governance is where the balance is set: for a given information type, the organisation decides which property may be spent to buy which, and records the decision. A control is never “secure” on its own — it protects a named property to a named level, at a stated cost.
A common misconception: “security means confidentiality”
The first mistake is to read security as secrecy. FIPS 199’s own worked example of public information assigns NOT APPLICABLE to confidentiality — there is nothing to disclose that is not already public — while integrity and availability are both rated MODERATE. A control bought for secrecy protects nothing there, while an unrecoverable or silently altered public page is still a serious loss.
The second mistake is to treat the three properties as three equal boxes to tick. Each information type carries its own level for each property, a system carries the highest of each, and a control for one property can weaken another — so the three cannot be ticked independently. “We do security” is not a statement that survives either mistake; the answer has to name which property, for which information, to which level.
What to remember
- Security protects three properties: confidentiality, integrity and availability.
- A loss of each is defined — unauthorized disclosure; unauthorized modification or destruction; disruption of access or use.
- Potential impact is assessed per property, per information type: LOW, MODERATE, HIGH — a limited, serious, or severe or catastrophic adverse effect.
- The properties are assessed separately but delivered together: a control that strengthens one can cost another, so security is a trade-off.
- “Security = confidentiality” is wrong: public information can have no confidentiality impact and still be critical for integrity and availability.
- NIST SP 800-30 Revision 1 defines information security risk as arising from the loss of these three properties.
Level and prerequisites
L1 — fundamentals: the vocabulary and the mental model, with no procedure, no configuration and no metrics. Prerequisites: none, though the next sheet in this batch (assets, processes, data and dependencies) names the things these properties are assessed for.
Where to go next
- Cybersecurity Governance — the area this sheet belongs to.
- The technical side of each property lives in other areas: segmentation and monitoring in Networking, hardening and restore in Server & Virtualization, inventory and oversight in AI & LLM.
References
- NIST, FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems (February 2004) — the three security objectives, the 44 U.S.C. §3542 definitions, the “loss of X is …” sentences, the LOW/MODERATE/HIGH potential-impact levels and the security-category format.
- NIST, Special Publication 800-30 Revision 1, Guide for Conducting Risk Assessments (September 2012) — the definition of risk, and of information security risk as risk arising from a loss of confidentiality, integrity or availability.
- NIST, FIPS Publication 200, Minimum Security Requirements for Federal Information and Information Systems (March 2006) — security categorization as the first step of the risk management process, and the mapping from impact levels to the low, moderate and high control baselines.