CIA Model for Enterprise Security
There are three main parts of cyber defense, or the CIA Model: Confidentiality, Integrity, and Availability (Donaldson et al., 2018). These three concepts make up the CIA triad, which an attacker looks for cracks in and defenders must constantly attend. If a company has poor confidentiality, their data or their customer data may get stolen. If there’s too much access in a company, people may be unnecessarily privileged to security systems or other network segments. If an attacker is able to modify data, such as in a (wo)man-in-the-middle attack, or by changing inputs in a database, the integrity of the security system is compromised (Donaldson et al., 2018).
Implementation Challenges
Three challenges associated with implementing the CIA triad in a cybersecurity program include people, financial backing, and public collaboration. Firstly, people are not perfect. There will always be instances of a policy well intended but thwarted by an individual making a mistake or being unaware of the consequences to their actions. The seven layers of the OSI Model are often covered profusely, but the eighth layer, the human layer, is rarely mentioned or accounted for. Many professionals assume that if they can set their networks up properly, it will compensate for any employee or customer ignorance, either innocent or negligent.
Secondly, many companies only have so much time, resources, employees, and money to pour into their cybersecurity programs. There’s only so much that can be done, and only so many hours in a day to do it. This leaves many companies in the middle of transitioning, or building their defenses. While all cybersecurity set ups should be constantly improving, leaving holes in the hopes that they simply won’t be attacked is not effective nor safe.
Thirdly, many companies have their cybersecurity personnel sign agreements which prevent them from discussing the issues their company has in their defenses. This keeps professionals from having proper discourse and sharing ideas that could lead to creative solutions and stronger defenses.
Some vulnerabilities in association with confidentiality include security architecture, network segmentation, and system administrators. Knowing exactly where sensitive data resides is one of the most important mitigations for a poor security architecture (Donaldson et al., 2018). Databases, servers, and backups need to be closely watched and protected. For example, if a system administrator knows they use Amazon Web Services for their servers, but doesn’t know where their servers are physically located, those devices are at risk (Tomsho, 2020). Network segmentation is useful for all parts of the CIA triad. Keeping one group of employees separated from another keeps a network organized and encourages a policy of least privilege. Most importantly for confidentiality, network segmentation can make it harder for an attacker who has accessed one part of the network, to get to another part (Tomsho, 2020).
Lastly, system administrators are refered to as the “achilles’ heel of most enterprises [because] if attackers can get access to [their] credentials, they can bypass all other data protections and frequently do so with little or no audit trail to reveal their actions (Donaldson et al., 2018).” There are simple solutions to this, such as giving each administrator a different privileged user account that is logged and audited with more care than an average user. Time restrictions can be put on when the account may be in use, multifactor authentication should be implemented, and passwords should be changed frequently (Donaldson et al., 2018).
Some vulnerabilities in association with integrity include political and reputational issues, publicly financial data, and under preparedness for ransomware attacks (Tomsho, 2020). Political instigators and sensationalized reputations can catch fire in the public discourse. If a company is targeted for political or activist reasons, the attackers can be inspired to risk everything in order to cause as much damage as possible. This can lead to vandalism, hijacking, fake news, and social disparity (Donaldson et al., 2018). Publicly financial data, while not as much an attraction for gossip, can lead to more sophisticated hackers looking for big payouts for richer victims. This works both ways with banks as well, because many money transactions happen online. The Sarbanes-Oxley regulations were put in place to protect financial data integrity for this very reason (Donaldson et al., 2018). Lastly, if a company isn’t prepared with proper backups for a ransomware attack, they could lose all their data.
Some vulnerabilities in association with availability include distributed denial of service attacks, targeted denial of service attacks, and physical destruction. “Distributed Denial of Service (DDoS) attacks are used to effectively disable services in the victim enterprise or country. These techniques have been used in the past several years, and they can take significant portions of the victim’s Internet capabilities offline for some time until they are mitigated. (Donaldson et al., 2018)”. A targeted DDoS attack usually pinpoint one company, resulting in a network having to be rebuilt if it can’t be recovered. Physical destruction goes along the same lines as sabotage or vandalism. If a company’s devices and data aren’t protected properly, and people have access who shouldn’t, a company can be completely deleted, unable to service their customers.
Attackers have the advantage of dark-web sales and high levels of public discourse for attack methods and scripts (Donaldson et al., 2018). There are libraries dedicated to brute forcing, videos that teach social engineering, and hacking classes available online. In order to keep networks and data from being accessed, changed, or stolen, the CIA triad should be a top priority for any cybersecurity professionals.
Donaldson, S. E., Siegel, S. G., Williams, C. K., & Aslam, A. (2018). Enterprise cybersecurity study guide : how to build a successful cyberdefense program against advanced threats. Apress.
Tomsho, G. (2020). Guide to networking essentials. Cengage Learning.