Confidentiality, Integrity,
and Availability

The CIA triad, security controls, defense-in-depth, and data classification law  ·  Approx. 2 class days

StarringConfidentiality · Integrity · AvailabilityPII → PHI → PCI

Use this as a quick reference for the CIA triad, security control types, defense-in-depth layers, and the data classification laws.

CIA Triad, Security Controls, and Data Classification infographic

🧭 Plot Summary

Almost every security control that exists is ultimately protecting one of three things — the CIA triad:

Confidentiality
Only authorized parties can access data
Integrity
Data stays accurate and untampered
Availability
Authorized users can get to data when needed

From there, you'll classify security controls two different ways — by type and by function — and see why a real organization layers several of them together in a defense-in-depth strategy rather than relying on any single control. You'll also revisit risk management, and learn to classify data — PII, PHI, PCI — and match each type to the law that actually governs it.

What you will do in this lesson

  • Explore the CIA triad on the PLTW virtual server — confidentiality, integrity, and availability.
  • Classify security controls by type (physical, technical, managerial) and by function (preventative, detective, corrective).
  • Learn why a defense-in-depth strategy layers multiple controls together.
  • Apply the four risk management strategies to real scenarios.
  • Classify data as PII, PHI, or PCI, and match each to the law that governs it.

Why it matters

This activity is dense on purpose — CIA, security controls, defense-in-depth, risk strategies, and data law all live here at once. The data law names in particular are a classic multiple-choice trap. Get them locked in now.

Self-Check Before You Roll On

Check off each item as you get there. These are not grades — they are your own signal.