- Meaning
- Four protective values of information security
- Values
- Availability, integrity, confidentiality, authenticity
- Use
- A yardstick for assessing incidents
- Related
- Cybersecurity, controls
- Updated
- June 2026
- Editorial team
- Compliance Compass
What are the security objectives?
Security objectives are the four values that information security is measured against: availability (systems and data are usable when they are needed), integrity (data are correct and unaltered), confidentiality (only authorised people have access) and authenticity (origin and genuineness can be proven). Together they form the frame that every security decision can be aligned to – from the risk assessment to the choice of concrete measures. German-language practice sums the four up in the memory aid VIVA; English has no equivalent acronym, so the objectives are named in full.
The four values in detail
- Availability: protection against outages, overload and DDoS attacks, so that services stay reachable.
- Integrity: protection against unnoticed or unauthorised alteration of data and configurations.
- Confidentiality: protection against unauthorised access and the unintended leakage of information.
- Authenticity: certainty about the origin and genuineness of data, messages and identities.
The security objectives and the CIA triad
Internationally the usual shorthand is the CIA triad (confidentiality, integrity, availability). NIS2 places a fourth value beside those three classics: authenticity, which Article 6 of the directive names alongside availability, integrity and confidentiality. It matters whenever manipulated emails or forged identities have to be recognised. German-language practice compresses the four into the memory aid VIVA, which works only in German; English has no such acronym. The standard ISO/IEC 27001 for information security management systems builds on the same objectives.
The security objectives as a yardstick
Security incidents almost always touch one or more of these values. The security objectives therefore serve as a practical yardstick for placing the impact and for choosing suitable Controls deliberately. The same question helps when classifying whether an incident is significant under NIS2 and therefore notifiable: which value was breached, and how badly?
A typical case: if ransomware encrypts the production data of a plant, two of the four values are hit at once: availability (the data can no longer be used) and integrity (they have been altered). That classification helps the team to judge the severity of the incident and to prioritise the right immediate measures, such as restoring from backups.
Further reading: ISO/IEC 27001 – information security management systems
Frequently asked questions
What are the four security objectives?
The four security objectives of information security are availability, integrity, confidentiality and authenticity. Availability means that systems and data are usable when they are needed; integrity that data stay correct and unaltered; confidentiality that only authorised people have access; authenticity that origin and genuineness can be proven. These are the values against which the protection of information is measured. Article 6 of Directive (EU) 2022/2555 names all four when it defines the security of network and information systems. German-language practice packs them into the memory aid VIVA; English has no equivalent acronym, so the four values are simply spelled out.
What are the security objectives used for?
The security objectives serve as a practical yardstick for placing the impact of a security incident and for choosing protective measures deliberately. Every incident can be judged by which of the four values – availability, integrity, confidentiality or authenticity – it breaches, and how badly: availability, for instance, in a DDoS attack. The same question helps when deciding whether an incident is significant under NIS2 and therefore has to be notified.
How do the security objectives relate to the CIA triad?
The CIA triad, the shorthand used internationally, covers confidentiality, integrity and availability. NIS2 places a fourth value beside those three: authenticity, the provable genuineness of origin and identity. Article 6 of the directive lists availability, authenticity, integrity and confidentiality side by side. That fourth dimension matters whenever manipulated emails or forged identities have to be recognised. German-language practice compresses all four into the memory aid VIVA, which works only in German; English has no such acronym, and CIA covers only three of the four values.