Glossary · Term

Security objectives explained

Security objectives – availability, integrity, confidentiality, authenticity: the four values that information security protects.

At a glance
Meaning
Four protective values of information security
Values
Availability, integrity, confidentiality, authenticity
Use
A yardstick for assessing incidents
Related
Cybersecurity, controls
Updated
June 2026
Editorial team
Compliance Compass

What are the security objectives?

Security objectives are the four values that information security is measured against: availability (systems and data are usable when they are needed), integrity (data are correct and unaltered), confidentiality (only authorised people have access) and authenticity (origin and genuineness can be proven). Together they form the frame that every security decision can be aligned to – from the risk assessment to the choice of concrete measures. German-language practice sums the four up in the memory aid VIVA; English has no equivalent acronym, so the objectives are named in full.

The four values in detail

The security objectives and the CIA triad

Internationally the usual shorthand is the CIA triad (confidentiality, integrity, availability). NIS2 places a fourth value beside those three classics: authenticity, which Article 6 of the directive names alongside availability, integrity and confidentiality. It matters whenever manipulated emails or forged identities have to be recognised. German-language practice compresses the four into the memory aid VIVA, which works only in German; English has no such acronym. The standard ISO/IEC 27001 for information security management systems builds on the same objectives.

The security objectives as a yardstick

Security incidents almost always touch one or more of these values. The security objectives therefore serve as a practical yardstick for placing the impact and for choosing suitable Controls deliberately. The same question helps when classifying whether an incident is significant under NIS2 and therefore notifiable: which value was breached, and how badly?

A typical case: if ransomware encrypts the production data of a plant, two of the four values are hit at once: availability (the data can no longer be used) and integrity (they have been altered). That classification helps the team to judge the severity of the incident and to prioritise the right immediate measures, such as restoring from backups.

Further reading: ISO/IEC 27001 – information security management systems

Frequently asked questions

What are the four security objectives?

The four security objectives of information security are availability, integrity, confidentiality and authenticity. Availability means that systems and data are usable when they are needed; integrity that data stay correct and unaltered; confidentiality that only authorised people have access; authenticity that origin and genuineness can be proven. These are the values against which the protection of information is measured. Article 6 of Directive (EU) 2022/2555 names all four when it defines the security of network and information systems. German-language practice packs them into the memory aid VIVA; English has no equivalent acronym, so the four values are simply spelled out.

What are the security objectives used for?

The security objectives serve as a practical yardstick for placing the impact of a security incident and for choosing protective measures deliberately. Every incident can be judged by which of the four values – availability, integrity, confidentiality or authenticity – it breaches, and how badly: availability, for instance, in a DDoS attack. The same question helps when deciding whether an incident is significant under NIS2 and therefore has to be notified.

How do the security objectives relate to the CIA triad?

The CIA triad, the shorthand used internationally, covers confidentiality, integrity and availability. NIS2 places a fourth value beside those three: authenticity, the provable genuineness of origin and identity. Article 6 of the directive lists availability, authenticity, integrity and confidentiality side by side. That fourth dimension matters whenever manipulated emails or forged identities have to be recognised. German-language practice compresses all four into the memory aid VIVA, which works only in German; English has no such acronym, and CIA covers only three of the four values.

Security objectives

Four values, one yardstick

Compliance Compass assesses risks and incidents along these security objectives – clearly and traceably.