CIANA
Field: Security · Also called: Five Pillars of Information Assurance, Five Pillars of Information Security
CIANA is an acronym for five information assurance properties: Confidentiality, Integrity, Availability, Non-Repudiation, and Authentication. It extends the three-property CIA triad.
The five properties
- Confidentiality: protecting information from those who shouldn’t see it
- Integrity: preventing information from being changed outside the intention of its owner
- Availability: making sure the system and its information are reachable by the people who need them
- Non-Repudiation: preventing someone from credibly denying an action they took
- Authentication: confirming a user is who they claim to be and that they are authorized to access a computing resource
Background
The CIA triad (Confidentiality, Integrity, Availability) is the older and more widely cited model. DoD Directive 8500.1 (2002) described Information Assurance in terms of all five properties. “Five Pillars” is a later teaching name for the same model.
… This combination produces layers of technical and non-technical solutions that: provide appropriate levels of confidentiality, integrity, authentication, non-repudiation, and availability; defend the perimeters of enclaves; provide appropriate degrees of protection to all enclaves and computing environments; and make appropriate use of supporting IA infrastructures, to include robust key management and incident detection and response. (DODD-8500-1, page 4)
Availability and accessibility
Availability is usually discussed in terms of uptime and outages. It can also apply when a resource is online but unusable by an authorized user, such as a document a screen reader cannot navigate. Rietta’s articles apply the availability property to digital accessibility on this basis.
Authentication & Authorization
Authentication and authorization are distinct in implementation, and control catalogs name them separately: FIPS 200, for example, has separate Identification and Authentication and Access Control requirements, and requires both. Within the CIANA framework, however, they are a single property. The DOD directive’s definition section specifically combined these concepts on page 20 of the same publication, stating that “…provide security services (e.g., confidentiality, authentication, integrity, access control, non-repudiation of data); correct known vulnerabilities; and/or provide layered defense against various categories of non-authorized or malicious penetrations of information systems or networks…” As a practical matter, authentication without authorization leads to insecure direct object reference vulnerabilities, a major data breach risk. See Authentication.
In Rietta’s application security training, the property is sometimes written as Authentication [& Authorization] to make this explicit.
Sources
- DoD Directive 8500.1, Information Assurance (IA), U.S. Department of Defense, 2002. Retrieved September 24, 2026.
See also
Go deeper
Articles
- Non-Repudiation in Cybersecurity September 16, 2026
- On Flock Cameras and "What Do You Have to Hide" September 15, 2026
- Threat Modeling for ADA/WCAG Compliance July 28, 2026
- The Five Pillars of Information Security (And Why We Audit Accessibility) July 25, 2026