Concept and mechanism
Confidentiality protects against inappropriate disclosure; integrity concerns modification and content trust; availability enables using a service when needed. An accessible file with unauthorized amount changes has an integrity problem even if its server is healthy. Do not infer disclosure or attacker identity without evidence. Authentication, authorization, and accounting are also distinct: identifying a person does not grant every action, and recording an attempt does not create permission. To apply requirements, distinguish guiding policy, specifying standards, and execution procedures. Having documents does not demonstrate controls were executed for every account.
Guided application
In a fictional support example, an analyst finds excessive access to another team’s documents. Report through the defined channel with minimal evidence rather than downloading the entire folder to prove the issue. Professional conduct requires accuracy, care with data, and respect for authorized scope. Connect threats to weaknesses and impact: malicious password use can exploit insufficient protection, but failed attempts establish neither data loss nor zero risk. Classify measures by mechanism: training is administrative, a door control is physical, and a firewall rule is technical. The same reasoning applies to AI: modified examples can damage suggestion integrity without an outage. Investigate origin and consequences before claiming sabotage or assigning responsibility.
Valid login and denied approval can demonstrate authentication and authorization working correctly.
Common pitfalls
Availability as complete security; technical access as ethical authorization; policy as execution proof; hypothesis as fact.
Related topics: Governance, continuity, and awareness · Identity and access lifecycle · Networks, cloud, and boundaries
Describe what evidence establishes and retain your role boundaries.
Reference: CC official examination outline PDF · CC examination outline effective 2026-09-01; PDF v01/2026