CIA Triad is Insufficient to Understand Web Application Risk, Use CIANA Instead
The classic CIA Triad, Confidentiality, Integrity, and Availability, is a good starting point, but it’s incomplete for how modern, internet-connected systems actually get attacked and defended. Non-Repudiation and Authentication earn their own pillars in the fuller CIANA model, because so much of modern risk lives exactly there. Read more in The Five Pillars of Information Security (And Why We Audit Accessibility).