Top
Week 4
Learning Aims and Objectives:
Aim:
In this week's page, students will learn how the CIA triad and IAAA model work together to provide effective security within digital systems.
Objectives:
1. By the end of this week's page students will be able to explain the principles of confidentiality, integrity and availability and how they interrelate within the CIA triad.
2. By the end of the week's page students will be able to describe how confidentiality is maintained by controlling who can access data and information.
3. By the end of the week's page students will be able to explain the difference between identification and authentication, including usernames, passwords, passphrases, biometrics and multi-factor authentication.
4. By the end of the week's page students will be able to explain how authorisation controls what authenticated users are permitted to access or do, including the use of role-based access and access control lists.
5. By the end of the week's page students will be able to explain how accountability is maintained through audit logs and user activity monitoring so that actions can be traced back to individual users.
8.4 Interrelationship of components required for effective security
8.4.1 Understand how the relationships in the CIA triad interrelate:

Confidentiality
o ensuring that data is kept private by controlling who has access to the data
Integrity
o ensuring that the data has not been tampered with; this can be done by maintaining confidentiality
Availability
o ensuring that data is available and useful; this can be done by ensuring integrity.
8.4.2 Understand the elements of the Identification Authentication Authorisation Accountability (IAAA) model, including the techniques used and their benefits and drawbacks:
Identification
o recognising the individual within a digital system
o knowledge-based identification, including username
o possession-based identification methods
o biometric-based ID methods
Authentication
o verifying the identity claimed during the identification phase
o multi-factor authentication methods
o passwords and pass phrases
o biometric authentication
Authorisation
o ensuring that authenticated users can only access resources and perform actions that they are permitted to
o role-based using the role of the user within the digital system
o access control lists
Accountability
o ensuring that any actions within a system can be traced back to the responsible user
o audit logs
o user activity monitoring.
Last Updated
2026-09-18 12:47:03
English and Maths
English
Maths
Stretch and Challenge
Stretch and Challenge
Homework
Homework
Equality and Diversity Calendar
How to's
How to's Coverage
Links to Learning Outcomes |
Links to Assessment Criteria |
|
|---|---|---|
Files that support this week
←
Prev