Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - CIA Triad and New Emerging Technologies: Big Data and IoT
Articles

CIA Triad and New Emerging Technologies: Big Data and IoT

ISBuzz TeamBy ISBuzz TeamOctober 13, 2015Updated:December 27, 20215 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
cia traid and new technologies
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

We all know that Confidentiality, Integrity and Availability, also known as the CIA triad, is simple and widely applicable security model. But is this simple security model is sufficient to address security challenges pose by new technologies such as Big Data and Internet of Things? Big Data poses extra challenges to this triad because of (1) enormous amount of data to be secured, (2) number of sources sending data and (3) variety of data formats. Similarly, Internet of Things (IoT) allows physical objects or “things” to collect and exchange data and thus will present different type of security risk such as privacy or safety issues.

For month of September, we ask our expert panel members if there is need to modify this CIA triad given these new emerging technologies and responses are below:

[su_box title=”Allan Pratt, Adjunct Faculty & InfoSecurity Strategist, Los Angeles City College & Consultant” style=”glass” box_color=”#a45bb4″ title_color=”#060706″]Allan Pratt MBAThe CIA triad is now outdated. There are a few other practices that should be added to the model. Within the last few years, thanks to e-commerce, authentication and nonrepudiation have slowly been added on at the periphery of CIA. But now it is time to add them officially to the security model. One more practice that should be added is Code Validation.

The 6 Points of Security

CIA traid and new technologies

 

The reason for this is quite clear. Except for internal bad actors, threats today come from a myriad of directions to find a company’s vulnerabilities in their software/firmware.

With Big Data, code validation (checking for and then plugging software vulnerabilities) is extremely important. Hundreds or even thousands of terabytes of data are being used to extrapolate information. And while there are many commercial database software programs out there, companies tend to write their own code or modify off the shelf software to get the functionality they need. Without code validation being a central tenant and a constant reminder of CIA, the idea of code validation may not be at the top of people’s minds. Bad code equals vulnerabilities which equals becoming a target. All of that data on those servers can be stolen, sold, used for blackmail or given away. Data has become a commodity. It is bought, sold, stolen, and sometimes give away. It might as well be gold on the commodities market. Keeping code validation a part of any software operation should be as important to the “C-Suite” level as it is to those working on the software lifecycle.

IoT – Internet of Things brings with it so many opportunities for device corruption that I will NEVER buy an IoT device until there is an official governing body and official rules that every manufacturer must follow. Devices going online today have very weak security and software that is easy to hack. There is a whole group of devices (baby monitors) that fail every security test thrown at them. There are no penalties companies that make them have to pay — neither monetary nor in sanctions if they consistently get hacked.

There are hundreds of manufacturers out there that are getting ready to unleash a broad spectrum of devices, from refrigerators to coffee pots, and they have no idea what they’re doing. If they are made to follow the security tenets and are required to check that the software in their devices pass strict guidelines, including verifying their code is sound, I would certainly feel better about those devices being in everybody’s homes and cars.

Let’s look at what happened to Fiat-Chrysler for a moment. Do you think they thought about firewalls, VLANS, airgapping and the code that runs the computers that their cars have become? In my personal opinion, no. Technology is advancing faster than our ability to govern it. But I think following some simple guidelines may go a long way to at least mitigating some of the damage an unpatched, unnoticed, unprepared for vulnerability may cause.[/su_box]

[su_box title=”Charles Sweeney, CEO, Bloxx” style=”glass” box_color=”#a45bb4″ title_color=”#060706″]Charles SweeneyAlongside the universally regarded pillars of confidentiality, integrity and availability, it could be argued that a fourth idea of flexibility should be added onto the security model. No matter how secure the environment is, data is no longer just collected, stored and retained, but needs to be used by businesses in order to provide the best service possible.

To utilise data securely, companies must be flexible in their methodologies in order to take full advantage of the latest technologies. Moving the data to the cloud, assigning ID keys in place of personally identifiable information and being able to replace, remove and update data are just a few techniques that can ensure it is as secure as possible, whilst also remaining insightful for your business.

If companies are to take full advantage of the accelerating IoT and big data revolution, then a large, static data silo will undoubtedly hold them back. Online information is no longer simply kept ‘on record’ but is actively engaged with by forward-thinking businesses. However, data that is being utilised and adding value to business service is without doubt more of a lucrative target to hackers and scammers, so it is vital that it can be manipulated, moved and encrypted with ease, ensuring it remains protected.[/su_box]To find out more about our panel members, please visit the biographies page.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Roblox Under Fire: Lawsuit Alleges Secret Data Tracking of Kids

May 13, 20254 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}