High School BeginnerModule B11Lesson 2 of 7

B11.2 Confidentiality, Integrity, and Availability in Data

Apply the CIA triad to files, records, cloud folders, shared documents, backups, and recovery decisions so data remains private enough, trustworthy, and available when needed.

Lesson Progress

Confidentiality, Integrity, and Availability in Data

High School BeginnerB11: Data Protection and Backups • Lesson 2 of 7

29% complete

Readiness Check

Before You Start

0/3 ready

Professional Hook

A File Can Be Private but Still Unreliable or Unavailable

A strongly protected file may still create a problem if no authorized person can access it during an emergency. A widely available file may still be unsafe if anyone can change it. The CIA triad helps defenders balance all three needs.

Safety reminder: every file, record, person, account, link, service, and incident in this lesson is fictional. Never expose real private information or change real sharing settings without permission.

Learning Objective

Explain confidentiality, integrity, availability, authorized access, and the CIA triad.

Learning Objective

Classify fictional incidents by which data-protection goal was affected.

Learning Objective

Choose access, versioning, backup, recovery, and sharing controls that balance all three goals.

Why This Matters

The Same Data Can Fail in Different Ways

A student record may be exposed to the wrong people, changed incorrectly, or unavailable during an important meeting. These are different problems, and each one requires a different defensive response.

Visual Diagram

The CIA Data Protection Flow

Strong data protection keeps information private enough, trustworthy, and available to the correct users at the correct time.

1

Protect confidentiality

Limit access, avoid public links, use trusted accounts, and share only with approved people.

2

Protect integrity

Use clear ownership, limited editing rights, version history, and verified copies.

3

Protect availability

Maintain reliable storage, protected backups, recovery options, and clear service responsibility.

4

Balance all three

Choose controls that protect privacy and accuracy without making authorized access impossible.

Defender rule: a control that protects one CIA goal should not unnecessarily damage the other two.

Core Concept

Protect Privacy, Trust, and Access Together

Confidentiality asks who should have access. Integrity asks whether the data is accurate and trustworthy. Availability asks whether authorized users can reach the information when they need it.

Key Vocabulary

Terms for the CIA Triad

Confidentiality

Keeping data available only to approved people, accounts, devices, or services.

Integrity

Keeping data accurate, complete, trustworthy, and protected from unauthorized or accidental changes.

Availability

Keeping data and services accessible to authorized users when they are needed.

CIA triad

A cybersecurity model that groups protection goals into confidentiality, integrity, and availability.

Authorized access

Permission granted to a person, account, device, or service for an approved purpose.

Version history

A record of earlier file versions that may help review changes or recover trusted content.

Technical Breakdown

Confidentiality, Integrity, and Availability Board

The CIA triad helps defenders explain what the data needs and which protection goal has been affected.

Confidentiality

Review question

Who can view, download, share, copy, or use the information?

Safer choice

Limit access to approved users, remove public links, and use trusted accounts and channels.

Integrity

Review question

Who can change the information, and how can trusted versions be identified or restored?

Safer choice

Limit editing, use version history, confirm ownership, and preserve verified copies.

Availability

Review question

Can authorized users access the data when needed if a device, account, file, or service fails?

Safer choice

Use reliable storage, protected backups, alternate access, and a recovery plan.

Balance

Review question

Does the protection reduce exposure without making legitimate use or recovery impossible?

Safer choice

Choose controls that match the data’s sensitivity, purpose, users, and recovery requirements.

Fake Dashboard

CIA Data Review Panel

This fictional panel compares confidentiality, integrity, availability, and situations where several goals overlap.

Fake Data

Private student record

Public sharing link allows anyone to view

Confidentiality issue. Remove public access and limit the file to authorized users.

Final project document

Older draft overwrites the approved version

Integrity issue. Use version history and restore the correct trusted version.

Club budget sheet

Storage service is unavailable before a meeting

Availability issue. Use approved backup access and follow the recovery plan.

Shared research folder

Everyone can edit every file

Integrity and confidentiality risk. Limit editing and access by role.

Encrypted archive

Only one person knows how to access it

Confidentiality may be strong, but availability is weak without approved recovery responsibility.

Fake Dashboard

Fake CIA Data Protection Dashboard

Training dashboard using fictional confidentiality, integrity, availability, access, version, and recovery evidence.

Data events reviewed

18

Fictional school, family, club, project, and organizational data scenarios.

CIA goals affected

27

Several incidents affected more than one protection goal.

Balanced responses

15

Access, versioning, backup, and recovery controls were matched to the incident.

Fake SOC Alert

Shared Project Folder Allows Public Viewing and Editing

Source: Fake Cloud Data Training • Time: 11:36 AM

High Severity
A fictional project folder contains private student work and allows anyone with the link to view, edit, and replace files.
Defensive recommendation: Remove public access, restore approved users, limit editing by role, review version history, and verify that trusted copies remain available.

Fake Log Panel

Fake CIA Incident Review Log

training-log-viewer.log
11:18:02 FOLDER name='project_team' owner='teacher'
11:21:17 SHARING scope='anyone_with_link' permission='edit'
11:24:41 CONFIDENTIALITY status='affected' unauthorized_view='possible'
11:27:55 INTEGRITY status='affected' unauthorized_changes='detected'
11:31:23 AVAILABILITY trusted_version='available_in_history'
11:36:09 RESPONSE public_link='removed' roles='restored' version='verified'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Which CIA Goals Are Affected?

A fictional club budget file is shared publicly.
Several numbers were changed by an unknown editor.
The approved version still exists in version history.
The club needs the file before a meeting in one hour.

What is the best conclusion and response?

Common Mistakes

Mistakes That Weaken CIA Protection

Treating confidentiality as the only data-protection goal.
Giving everyone edit access when most users need view-only access.
Restoring an old file without confirming it is the trusted version.
Keeping the only copy of important data in one account or on one device.
Making data so restricted that authorized users cannot access it when needed.
Ignoring accidental changes because no attacker was involved.

Safe Defensive Lab

Classify Fictional Data Incidents With the CIA Triad

Fake Incident Set

CIA Data Review

A fictional student reviews a public private-file link, an overwritten project, an unavailable cloud folder, a broadly editable budget, and a protected archive with no recovery owner.

Defender Review Steps

  • Identify the data owner and approved users.
  • Classify each event as confidentiality, integrity, availability, or several goals.
  • Explain the possible impact.
  • Choose access, version, backup, or recovery controls.
  • Verify that the response protects all three goals appropriately.

Scenario Decision Lab

A Final Project Is Replaced by an Older Draft

A fictional student opens a shared project folder and discovers that the final approved file has been overwritten by an older version.

Scenario Decision Lab

A Protected Archive Has No Recovery Owner

A fictional organization stores an important archive in a protected account, but only one person knows how to access it.

Defender Habits

CIA Data Protection Checklist

Check Your Understanding

B11.2 Mini Quiz: Confidentiality, Integrity, and Availability in Data

Choose your answers first. Explanations appear only after submission.

1. What does confidentiality protect?

2. What does integrity protect?

3. What does availability protect?

4. A public link exposes a private file. Which CIA goal is affected most directly?

5. An older draft replaces the final approved file. Which CIA goal is affected most directly?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional CIA data review. Include six data scenarios, the affected CIA goal or goals, impact, approved users, recommended control, recovery need, and verification step.

Use fictional people, accounts, files, services, records, and organizations only.
Do not include real private information, cloud links, credentials, or school records.
Explain how each response balances confidentiality, integrity, and availability.

Key Takeaways

What You Should Remember

1.Confidentiality limits data access to approved users and purposes.
2.Integrity protects the accuracy, completeness, and trustworthiness of information.
3.Availability ensures authorized users can access data and services when needed.
4.One incident may affect several CIA goals at the same time.
5.Strong controls balance privacy, trust, access, backup, and recovery requirements.

Navigation

Continue Module B11