Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Cyber Security
Introduction to Cyber Security: Meaning, Objectives and CIA Triad
Updated 11 October 2026 · Fact-checked
Cyber security is the practice of protecting computers, networks, programs and data from unauthorised access, damage, misuse or disruption. Its core objectives are the CIA triad: confidentiality (only authorised people see data), integrity (data stays accurate and unaltered) and availability (systems and data are usable when needed). To answer exam questions, define, state objectives, then apply to facts.
Understand Introduction to Cyber Security
Cyber security means protecting digital assets from harm. These assets include computers, networks, software, servers, cloud services, mobile devices and the data they hold. The harm can be theft, alteration, destruction, or loss of access. Cyber security covers technology, people and processes together. A strong firewall does not help if an employee shares a password.
The scope is wide. It includes network security, application security, information (data) security, endpoint security, cloud security, identity and access management, and incident response and recovery. It also covers policies, staff awareness, and compliance with law. Cyber security is not only an IT matter. For a company, it is a governance and risk matter that the board must oversee.
The central idea is the CIA triad. Confidentiality means information is disclosed only to authorised persons. Tools: passwords, encryption, access controls. Integrity means information is accurate, complete and not changed without authority. Tools: hashing, digital signatures, audit logs, version control. Availability means authorised users can reach systems and data when needed. Tools: backups, redundancy, disaster recovery, protection against denial-of-service attacks.
Other objectives are often added to the triad. These include authentication (proving who you are), authorisation (what you may do), and non-repudiation (a person cannot later deny an action, for example a signed transaction). Accountability and privacy are also commonly listed.
Organisations need cyber security for several reasons: to protect customer and business data, to keep operations running, to avoid financial loss and reputational damage, to meet legal and regulatory duties, and to keep stakeholder trust. As a Company Secretary, you advise the board on these duties and on compliance.
Key rules to remember
- CIA triad
- Cyber security objectives = Confidentiality + Integrity + Availability
- Learn each term with its meaning, a control, and a breach example.
- Confidentiality
- Only authorised persons can access information
- Breach example: a data leak. Controls: encryption, access control, passwords.
- Integrity
- Information is accurate and changed only by authorised persons
- Breach example: altering a bank record. Controls: hashing, digital signature, audit trail.
- Availability
- Authorised users get timely access to systems and data
- Breach example: denial-of-service or ransomware. Controls: backups, redundancy, recovery plans.
- Extended objectives
- Authentication, authorisation, non-repudiation, accountability
- Mention these as additions to the triad, not replacements.
How to solve Introduction to Cyber Security questions
Use this method for any theory or case question on introduction to cyber security.
- 1Read the question and mark the verb: define, explain, discuss, or advise.
- 2Start with a one or two line definition of cyber security.
- 3State the relevant objectives or the CIA triad, one line each.
- 4Link each element to a control or example that fits the facts given.
- 5In a case question, identify which element was breached: confidentiality, integrity or availability, or more than one.
- 6Explain the business impact: loss, legal exposure, reputation, trust.
- 7Close with a short conclusion or recommendation, such as policy, access control, backup or staff training.
Quickest way: Define, triad, apply
When to use it: Use when time is short, especially for a 5 to 8 mark short note or a short case.
- Write the definition in one sentence.
- List C, I and A with a one-line meaning each.
- Add one example and one control for each element.
- Tag the case fact to the element breached.
- End with one line on why the organisation needs cyber security.
Common mistakes in Introduction to Cyber Security
Confusing integrity with confidentiality
Both sound like keeping data safe, so students treat them as the same.
Fix: Confidentiality is about who can see data. Integrity is about whether data is correct and unchanged.
Treating availability as only a backup issue
Students link availability only with data recovery.
Fix: Availability means timely access. It covers uptime, redundancy, attack protection and recovery plans.
Defining cyber security as only technology
Textbook examples focus on firewalls and antivirus.
Fix: Say it covers technology, people and processes, including policy, training and compliance.
Writing a definition with no objectives or example
Students stop once the definition is written.
Fix: Always follow the definition with the triad and at least one example, as marks are for application.
Forcing every case into one triad element
Students look for a single answer.
Fix: Check all three. Ransomware, for example, hits availability and may also hit confidentiality if data is stolen.
Worked examples
Example 1
Explain the CIA triad with one example each. (Short note)
Show the solution
- Define: the CIA triad is the three core objectives of cyber security.
- Confidentiality: only authorised persons see information. Example: a bank encrypts customer account data so outsiders cannot read it.
- Integrity: data remains accurate and is changed only with authority. Example: a company uses audit logs and digital signatures so ledger entries cannot be altered silently.
- Availability: systems and data are accessible when needed. Example: an e-commerce firm keeps backup servers so its site works during a failure or attack.
- Conclude: a weakness in any one element weakens overall security.
Answer: The CIA triad means confidentiality (restricted access), integrity (accuracy and authorised change only) and availability (timely access). Each is protected by specific controls, and all three must be balanced.
Example 2
A Pune-based company finds that an employee copied its customer list and sent it to a competitor. Separately, its payroll server was down for two days after an attack. Identify which CIA elements were affected and suggest measures.
Show the solution
- Customer list copied and sent out: this is a breach of confidentiality, as unauthorised disclosure occurred.
- Payroll server down for two days: this is a breach of availability, as authorised users could not access the system.
- Measure for confidentiality: role-based access control, encryption, data-loss prevention tools, and confidentiality agreements with staff.
- Measure for availability: regular backups, redundant servers, a tested disaster recovery plan and attack monitoring.
- Governance step: the board should approve a cyber security policy and review incidents.
Answer: The copying of the customer list breached confidentiality and the two-day payroll outage breached availability. The company should apply access controls and encryption, and maintain backups and a recovery plan, under a board-approved policy.
Exam tips
- Always write the full terms (confidentiality, integrity, availability) before using CIA, and give a one-line meaning of each.
- In case questions, name the element breached before suggesting remedies. It shows analysis.
- Add authentication, authorisation and non-repudiation when a question asks for objectives, to show wider coverage.
- Keep controls practical: access control, encryption, backups, training, policy. Examiners reward usable advice.
- Link your closing line to the board's or company secretary's role in oversight and compliance.
Practice questions from Cyber Security
- Employees of a Pune logistics firm receive an email that appears to come from the company's CEO, with a link to a page that imitates the cor…
- A Mumbai company's employee finds her files unreadable and a message demanding payment in cryptocurrency for a decryption key. Investigation…
- An attacker enters the string ' OR '1'='1 into the login field of a company's web portal and gains access without a valid password, because …
- Under the CERT-In Directions of 2022, for how long must logs of all ICT systems be maintained securely, within the Indian jurisdiction?
- A company detects ransomware encrypting files on one finance-department server connected to the corporate network. The incident team must ac…
Introduction to Cyber Security in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Introduction to Cyber Security: frequently asked questions
What is cyber security in simple words?
It is protecting computers, networks and data from unauthorised access, damage or disruption. It combines technology, people and processes. For a company, it also means meeting legal and governance duties.
What does the CIA triad stand for?
It stands for confidentiality, integrity and availability. These are the three core objectives of information security. Every control is meant to protect at least one of them.
Is the CIA triad the only objective of cyber security?
No. The triad is the core, but authentication, authorisation, non-repudiation and accountability are commonly added. Mention them as extensions in longer answers.
Why does a company secretary need to know cyber security?
Cyber risk is a governance and compliance issue that the board must oversee. A company secretary advises on policies, incident reporting and legal duties. The paper tests this through case-based questions.