Fundamentals of Information Security
Welcome to this comprehensive course on the core principles of information security. Whether you are a student, a professional, or simply curious about how data is protected, this guide will…

Which element of the Parkerian Hexad directly addresses the problem of a stolen backup drive?
A developer implements a function that writes logs for every user action but forgets to encrypt those logs. Which security principle is being violated?
In the Bell‑LaPadula model, which rule prevents a high‑clearance subject from leaking information to a lower level?
Which DAD Triad attack corresponds to a ransomware incident that encrypts data and makes it inaccessible?
A cloud service provider isolates each customer's workload in separate virtual machines on the same hardware. Which security principle does this primarily implement?
When applying the principle of Least Privilege, which of the following is the most appropriate action for a user who only needs to view reports?
Which security model uses Constrained Data Items (CDI) and Integrity Verification Procedures (IVP) to enforce integrity?
In a Zero Trust architecture, which of the following statements best describes the default stance toward network traffic?
A system implements multiple firewalls, intrusion detection systems, and encrypted backups to protect data. Which security concept does this layered approach exemplify?
Fundamentals of Information Security: Key Concepts Explained
Welcome to this comprehensive course on the core principles of information security. Whether you are a student, a professional, or simply curious about how data is protected, this guide will walk you through essential concepts such as the CIA triad, the Parkerian Hexad, security models, and practical principles like Least Privilege and virtualization.
1. The CIA Triad – Confidentiality, Integrity, Availability
The CIA triad is the cornerstone of information security. Each element addresses a distinct risk:
- Confidentiality: Ensures that only authorized individuals can access data.
- Integrity: Guarantees that data remains accurate and unaltered.
- Availability: Keeps information accessible when needed.
Example: In a hospital, a patient’s medical record must retain its original content after submission. This requirement highlights Integrity – any unauthorized change must be detectable.
Memory aid: “I’m unchanged” (I = Integrity) helps you remember that integrity means the data stays the same.
2. Extending the Triad: The Parkerian Hexad
The Parkerian Hexad adds three more properties to the classic CIA model, providing a richer view of data protection:
- Possession: Physical control over information.
- Authenticity: Assurance that data originates from a trusted source.
- Utility: The data must be usable for its intended purpose.
Scenario: A stolen backup drive illustrates a breach of Possession. The data was physically taken, regardless of its confidentiality or availability.
Memory aid: “P” for Possession is also “P” for “Porta via” (taken away).
3. Security Principles in Practice
3.1 Attack Surface Minimisation
When developers log user actions without encrypting those logs, they unintentionally enlarge the attack surface. Attack surface minimisation means reducing the amount of exposed data that attackers could exploit.
Tip: Think of logs as windows – if you don’t close (encrypt) them, anyone can look inside.
3.2 Least Privilege
Least Privilege dictates that users receive only the permissions necessary to perform their tasks. For a user who only needs to view reports, the correct approach is to grant read‑only access to the reporting database.
Memory aid: “L = LS (Least privilege, Solo lettura).”
3.3 Virtualization and Isolation
Cloud providers often isolate each customer’s workload using separate virtual machines (VMs). This isolation is a direct application of the virtualization principle, creating sandboxed environments that prevent one tenant from affecting another.
Memory aid: V for Virtualization = V for “Vaschetti” (individual containers).
4. Formal Security Models
4.1 Bell‑LaPadula Model
The Bell‑LaPadula model focuses on confidentiality. Its two core rules are:
- Simple Security Property (no read up): Subjects cannot read data at a higher security level.
- Star (*) Security Property (no write down): Subjects cannot write data to a lower security level, preventing leakage.
The Star Security Property stops a high‑clearance subject from leaking information to a lower level.
Memory aid: “Star = * (write down) → prohibited.”
4.2 Clark‑Wilson Model
Unlike Bell‑LaPadula, the Clark‑Wilson model enforces data integrity through:
- Constrained Data Items (CDI): Sensitive data that must remain consistent.
- Integrity Verification Procedures (IVP): Checks that ensure CDIs are not corrupted.
- Well‑formed transactions performed by certified users.
This model is ideal for environments where data correctness is critical, such as financial systems.
Memory aid: “Clark‑Wilson = Constrained (C) and Well‑formed (W).”
5. The DAD Triad – A Modern View of Threats
Beyond confidentiality, integrity, and availability, the DAD triad categorises attacks as:
- Destruction/Denial: Rendering data unavailable (e.g., ransomware).
- Alteration: Unauthorized modification of data.
- Disclosure: Exposing data to unauthorized parties.
Ransomware encrypts files and makes them inaccessible, which aligns with the Destruction/Denial category.
6. Putting It All Together – Study Checklist
- Identify which CIA property is most relevant in a given scenario.
- Recognise when the Parkerian Hexad adds extra protection requirements.
- Apply attack surface minimisation by encrypting logs and limiting exposed data.
- Implement Least Privilege by granting only the necessary permissions.
- Use virtualization to isolate workloads in multi‑tenant cloud environments.
- Differentiate between Bell‑LaPadula (confidentiality) and Clark‑Wilson (integrity) models.
- Classify ransomware as a Destruction/Denial attack in the DAD triad.
7. Frequently Asked Questions (FAQ)
What is the difference between Confidentiality and Possession?
Confidentiality protects data from unauthorized viewing, while Possession concerns the physical control of the data. A stolen backup drive violates Possession but may still be encrypted, preserving confidentiality.
Why is the Star Security Property important?
It prevents high‑level subjects from writing data to lower security levels, thereby avoiding accidental or malicious leakage of sensitive information.
How does virtualization enhance security?
By creating isolated virtual machines, virtualization ensures that a breach in one tenant’s environment does not affect others, effectively sandboxing workloads.
8. Final Thoughts
Mastering these concepts equips you with a solid foundation to evaluate, design, and implement secure systems. Remember to use the memory aids, revisit the checklist, and apply the principles in real‑world scenarios to reinforce your learning.
