What is the CIA triad?
The CIA triad is the foundational model of information security that defines three goals: the confidentiality, integrity and availability of information and systems. Every security control, from a password to a firewall, contributes to at least one of these three goals. In the Netherlands the same model is known as BIV, after the Dutch words for availability, integrity and confidentiality. In OT environments the priorities are reversed to AIC, with safety as an overarching goal above all three.
π§ What do confidentiality, integrity and availability mean?
- Confidentiality β only authorised people and systems can access information. Think of recipes, PLC code, network diagrams and passwords.
- Integrity β information and systems are accurate, complete and not modified without authorisation. In OT this means setpoints, measured values, control logic and firmware.
- Availability β information and systems can be used when they are needed. For a process plant this means the control system runs around the clock and responds within the required time.
The vocabulary standard ISO/IEC 27000, which underpins ISO 27001, literally defines information security as the preservation of confidentiality, integrity and availability of information.
π°οΈ Where does the CIA triad come from?
The idea predates the acronym. The US Anderson Report of 1972 and the 1975 paper The Protection of Information in Computer Systems by Saltzer and Schroeder already described three kinds of violation: unauthorised release, unauthorised modification and unauthorised denial of use. The acronym CIA is attributed to Steve Lipner, around 1986. Since then the triad has sat at the heart of almost every security framework, from the ISO 27000 series to the US FIPS 199 categorisation and the Dutch government baseline BIO.
π Why does OT reverse the order to AIC?
In office IT a data breach is usually the biggest concern, so confidentiality comes first. In OT the system controls a physical process: an outage or manipulation can cause lost production, environmental damage or injury. NIST SP 800-82 Rev. 3 (2023) therefore states that OT puts integrity and availability ahead of confidentiality, with safety as an overarching priority. Hence the term AIC triad.
| Aspect | Office IT (CIA) | OT (AIC + safety) |
|---|---|---|
| Top priority | Confidentiality: no data breach | Safety of people, environment and plant |
| Availability | Hours of downtime often acceptable | An outage stops the process; restarting takes hours to days |
| Integrity | Correct database and financial records | Correct setpoints, measured values and control logic |
| Confidentiality | Personal data, contracts | Recipes, PLC code, network design |
| Rebooting as a fix | Common | Only within a planned maintenance window |
| Typical system lifetime | 3β5 years | 15β30 years |
Note that the order is a rule of thumb, not a law. Many OT specialists rank integrity equal to, or even above, availability. A plant running on manipulated measurements is more dangerous than one that has stopped safely. This is most obvious for a safety instrumented system: there, the integrity of the safety function matters more than keeping the process running.
π§± What extensions to the CIA triad exist?
The triad does not cover everything. In 1998 Donn Parker proposed the Parkerian hexad in his book Fighting Computer Crime, with six elements:
- Confidentiality, integrity and availability β the classic three
- Possession or control β who holds the data or system, even if nobody has read it
- Authenticity β does a command or message really come from the sender it appears to come from
- Utility β is the information still usable, for example a backup whose decryption key has been lost
Many frameworks also add non-repudiation: a user cannot later deny having performed an action. In OT, authenticity and non-repudiation matter most for changes to PLC logic and for commands sent to field devices, which many classic industrial protocols, such as Modbus, do not verify.
π§ How do the IEC 62443 requirements map to the CIA triad?
The IEC 62443 series does not work with C, I and A directly but with seven foundational requirements (FRs). IEC 62443-3-3 elaborates them into system requirements per security level. Their relation to the triad:
| FR | Name | Main CIA goal |
|---|---|---|
| FR1 | Identification and authentication control | Confidentiality and integrity (who may access) |
| FR2 | Use control | Integrity (what a user may do) |
| FR3 | System integrity | Integrity |
| FR4 | Data confidentiality | Confidentiality |
| FR5 | Restricted data flow | Confidentiality and availability (segmentation limits spread) |
| FR6 | Timely response to events | Integrity and availability (detect and recover in time) |
| FR7 | Resource availability | Availability |
Strikingly, only one of the seven FRs is purely about confidentiality, while integrity and availability recur in nearly all of the others. FR5 underpins the zones and conduits model.
β οΈ Which OT incidents violated which CIA goal?
| Goal | Incident | What happened |
|---|---|---|
| Integrity | Stuxnet (discovered 2010) | Disrupted centrifuges at Natanz by changing rotor speeds (1410 Hz and 2 Hz) and raising cascade pressure; during the attack the control logic and operators were fed recorded normal values |
| Integrity and safety | TRITON (2017) | Tried to reprogram the Triconex safety controllers of a Saudi petrochemical plant; a bug triggered a safe shutdown |
| Availability | Colonial Pipeline (2021) | Ransomware on the IT network; the largest fuel pipeline in the US was shut down as a precaution for six days |
| Availability | NotPetya (2017) | A wiper that halted Maersk, among others, including its Maasvlakte terminals in Rotterdam for over a week; total damage around 10 billion dollars |
| Confidentiality | Havex (2011β2014) | Trojanised installers from three European ICS vendors; a module scanned the network for OPC servers and sent the results to the attackers |
π οΈ How do you classify an OT system using CIA ratings?
A CIA (or BIV) classification determines, per aspect, how strongly a system needs protecting. Dutch government bodies often use a scale of 1 to 3 per letter, where 111 is low and 333 is maximum. Here is how you would approach it for, say, the SCADA system of a sewage pumping station:
- Define the scope β which components, networks and data belong to the system, and which process does it control?
- Assess the impact per aspect β use a business impact analysis: what happens after an outage of an hour, a day, a week? What if setpoints change unnoticed? What if the network design leaks?
- Weigh safety separately β if a violation can cause injury or environmental harm, integrity or availability automatically gets the highest rating.
- Apply the high-water mark β the most severe aspect sets the overall level, as in the US FIPS 199 and FIPS 200.
- Translate into controls β link the classification to a target security level per zone in the risk assessment under IEC 62443-3-2.
- Record and review β document the decision and repeat the classification after every major change.
A typical result for such a pumping station is A3, I3, C2: an outage or manipulation can cause sewer overflows and flooding, affecting the environment and public health, whereas leaked drawings help an attacker but cause no harm by themselves. For Dutch public bodies, BIO2, adopted on 23 September 2025, is risk-based: the old fixed baseline security levels have gone, but the CIA trade-off remains the starting point.
π Does confidentiality not matter in OT?
That is a persistent misconception. Confidentiality ranks lower in OT, but it is far from irrelevant:
- Reconnaissance precedes sabotage β attacks such as Stuxnet and TRITON began by gathering design data and configurations. Leaking network plans and PLC programs makes the next attack easier.
- Intellectual property β recipes, process parameters and batch formulas are often a plantβs most valuable business data.
- Credentials β a leaked password for remote access violates confidentiality first, and integrity and availability right after.
Encryption and access control therefore belong in OT too, provided they do not jeopardise the real-time requirements of the process.
β Frequently asked questions
What is the difference between CIA and BIV?
CIA and BIV are the same model in a different language and order. CIA stands for confidentiality, integrity and availability; BIV is the Dutch abbreviation for beschikbaarheid, integriteit and vertrouwelijkheid. The Dutch government uses BIV in the BIO baseline and in BIV classifications.
What does AIC mean in OT security?
AIC is the CIA triad in reverse order: availability, integrity, confidentiality. The term signals that OT systems above all need to keep running and process correct values, while confidentiality carries less weight. Safety sits above all three.
Where does safety fit in the CIA triad?
Safety is formally not part of the CIA triad, but in OT it is treated as an overarching goal above all three. NIST SP 800-82 explicitly names safety as an overarching priority. In OT, a security control must never compromise a safety function.
Is the Parkerian hexad better than the CIA triad?
The Parkerian hexad is an extension of the CIA triad rather than a replacement, adding possession, authenticity and utility. For OT, authenticity is the most useful addition, because many industrial protocols do not check who sends a command. In standards and legislation the CIA triad remains the common model.
How does IEC 62443 relate to the CIA triad?
IEC 62443 translates the CIA triad into seven foundational requirements, from identification and authentication control (FR1) to resource availability (FR7). FR3 covers integrity, FR4 confidentiality and FR7 availability, while the remaining FRs support several goals at once.
Which CIA goal did Stuxnet violate?
Stuxnet mainly violated the integrity of the process: it manipulated centrifuge speeds and pressures while feeding the control logic and operators recorded normal values. That makes Stuxnet the textbook example of an integrity attack on OT, with physical damage as the result.
π In summary
The CIA triad describes confidentiality, integrity and availability; in OT the order is reversed to AIC, with safety above all three. Use a CIA classification to decide which aspect weighs heaviest for each system, translate it into controls per zone through IEC 62443, and do not neglect confidentiality: reconnaissance is the first step of every OT attack.
