Get the App
SLTechnology News&Howtos  ›  Network Security  › 

AIC triple

Shulou Source: shulou.com Published: 2022-06-01 04:30:24 10月01日 Update

In network security, the core goal is to provide availability, integrity, and confidentiality for critical assets (AIC triple: Availability, integrity, confidentiality).

Availability (Availability)

Protection ensures that authorized users have timely and reliable access to data and resources. For example, to ensure the stability, disaster tolerance and sustainable operation of the network, in order to achieve the above points, it must be the combination of security personnel and technical personnel, and the combination of operating environment and available technology under the designation of the security system, in order to achieve good results.

Integrity (Integrity)

Integrity means ensuring the accuracy and reliability of information and systems, and prohibiting unauthorized changes to data. In this regard, in response to the actual situation, simplify the functions of users, only want to provide a small number of necessary options, so as to quantitatively reduce the occurrence of errors. And restrict the user's view and access to the key files of the system, and provide a mechanism to check whether the input value is valid and reasonable. The database should only allow authorized users to modify the data, while the transmitted data should be protected by encryption or other mechanisms.

Confidentiality (Confidentiality)

Confidentiality ensures that the necessary security is implemented at every intersection of data processing and unauthorized disclosure is organized.

For confidentiality, you can use the following methods:

1. Encryption during storage and data transfer

two。 Use strict access control and data classification

3. And volunteer training on appropriate data protection measures

Some measures against the AIC Triple principle

Usability

≯ redundant Array of inexpensive disks (RAID)

≯ cluster

≯ load balancing

≯ redundant data and power supply

≯ software and data backup

≯ co-location and offsite backup facilities

≯ rollback function

≯ failover configuration

Integrity

≯ hash (data integrity)

≯ configuration Management (system Integrity)

≯ change control (process integrity)

≯ access Control (physical and Technical)

≯ software digital signature

≯ Transport CRC (Cyclic Redundancy Check) function

Confidentiality

≯ encrypts idle data (entire disk, database)

≯ encrypts data in transit (IPSec, SSL, PPTP, SSH)

≯ access control

Tags: Data integrity confidentiality security user transmission protection encryption control function availability technology system ternary necessity personnel information critical redundancy measures Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MariaDB Huawei Shulou Tech Info macOS OPPO Reno