Learning path

Full curriculum

Full curriculum

Unit content

Security goals: confidentiality, integrity and availability

Computer security is about preserving properties that matter even when failures or adversaries are present.

Three core goals are:

  • confidentiality: information is not disclosed to unauthorized parties;
  • integrity: information and system state are not changed in unauthorized ways;
  • availability: authorized users can obtain the service or data they are supposed to have.

These goals can conflict. Encrypting a backup may improve confidentiality but make recovery harder if the key is lost. Aggressive availability mechanisms can increase the number of replicas that must be protected.

Security goals must therefore be stated for a particular asset and context. “Secure” is not a single property: a design may preserve confidentiality while failing integrity, or resist tampering while remaining easy to deny service.

Identity checks, permission checks, auditing and cryptographic mechanisms can help enforce security goals; they are mechanisms rather than the goals themselves.