Top

Week 4

Learning Aims and Objectives:

Aim:

In this week's page, students will learn how the CIA triad and IAAA model work together to provide effective security within digital systems.

Objectives:

1. By the end of this week's page students will be able to explain the principles of confidentiality, integrity and availability and how they interrelate within the CIA triad.

2. By the end of the week's page students will be able to describe how confidentiality is maintained by controlling who can access data and information.

3. By the end of the week's page students will be able to explain the difference between identification and authentication, including usernames, passwords, passphrases, biometrics and multi-factor authentication.

4. By the end of the week's page students will be able to explain how authorisation controls what authenticated users are permitted to access or do, including the use of role-based access and access control lists.

5. By the end of the week's page students will be able to explain how accountability is maintained through audit logs and user activity monitoring so that actions can be traced back to individual users.

8.4 Interrelationship of components required for effective security

8.4.1 Understand how the relationships in the CIA triad interrelate:

Confidentiality

o ensuring that data is kept private by controlling who has access to the data

Integrity

o ensuring that the data has not been tampered with; this can be done by maintaining confidentiality

Availability

o ensuring that data is available and useful; this can be done by ensuring integrity.

 

8.4.2 Understand the elements of the Identification Authentication Authorisation Accountability (IAAA) model, including the techniques used and their benefits and drawbacks:

Identification

o recognising the individual within a digital system

o knowledge-based identification, including username

o possession-based identification methods

o biometric-based ID methods

Authentication

o verifying the identity claimed during the identification phase

o multi-factor authentication methods

o passwords and pass phrases

o biometric authentication

Authorisation

o ensuring that authenticated users can only access resources and perform actions that they are permitted to

o role-based using the role of the user within the digital system

o access control lists

Accountability

o ensuring that any actions within a system can be traced back to the responsible user

o audit logs

o user activity monitoring.


Last Updated
2026-09-18 12:47:03

English and Maths

English


Maths


Stretch and Challenge

Stretch and Challenge


Homework

Homework


Equality and Diversity Calendar
How to's

How to's Coverage





Links to Learning Outcomes

Links to Assessment Criteria

 


Files that support this week


| | | | |

Prev