Lesson 1 of 12 — Security Fundamentals
The CIA Triad, Non-Repudiation, Security Control Categories, and Security Control Functional Types — the conceptual foundation every security professional builds from.
Every security decision a professional makes — whether selecting a firewall rule, writing an incident response procedure, or designing an access control model — ultimately traces back to a handful of foundational principles. The CIA Triad defines what we are protecting. The concept of Non-Repudiation tells us how accountability is enforced. Security Control Categories explain who or what implements a safeguard, and Functional Types tell us when and how that safeguard engages.
CompTIA Security+ SY0-701 tests your ability to recognize these frameworks in scenario-based questions — meaning you will not simply recall a definition but will apply these concepts to realistic situations like a working security analyst. This lesson builds the mental model you will use for every subsequent topic in the course. Master this vocabulary now, and the more advanced domains (threat analysis, architecture, operations) will click into place far more easily.
The three core security properties every professional must understand — plus the cryptographic guarantee of accountability.
Confidentiality prevents unauthorized disclosure. Integrity prevents unauthorized modification. Availability ensures authorized users have timely access. Non-Repudiation ensures no party can deny their actions — enforced by digital signatures and audit trails.
Managerial, Operational, Technical, and Physical — four implementation perspectives that classify who or what enforces a control.
Managerial controls are policy-driven. Operational controls are human-executed day-to-day. Technical controls are automated hardware/software mechanisms. Physical controls are tangible barriers protecting facilities and hardware.
Preventive, Detective, Corrective, Deterrent, Directive, and Compensating — six roles a control can play in your defense strategy.
Controls don't just exist — they act. They can prevent events, detect them, correct damage, deter attackers, direct behavior, or compensate when preferred controls are unavailable. One physical device can serve multiple functional roles simultaneously.
Foundational properties defining what security protects and why accountability matters
The CIA Triad is the bedrock of information security. Every control, policy, and technology exists to protect one or more of these three properties. Understanding them — and knowing how to recognize violations — is tested throughout the Security+ exam.
Confidentiality ensures that information is accessible only to those authorized to view it. It prevents unauthorized disclosure — whether intentional (a hacker exfiltrating data) or unintentional (an employee leaving a sensitive report on a shared drive).
Integrity ensures that data remains accurate, consistent, and unaltered except through authorized processes. It protects information from unauthorized modification, corruption, or deletion — by attackers or by system failures.
Availability ensures that systems, data, and services are accessible to authorized users when needed. Even perfectly confidential and integral data is useless if a DoS attack or hardware failure takes it offline.
Non-Repudiation guarantees that a party cannot deny having performed an action. It is the security property that makes legally and operationally binding digital transactions possible — from signing a contract to authorizing a wire transfer.
Four implementation perspectives: who or what enforces the control
Security controls are grouped by how they are implemented — the people, processes, technology, or physical mechanisms that enforce them. Understanding categories helps security professionals build layered defenses by selecting controls from multiple implementation perspectives.
| Category | Implemented By | Focus | Examples |
|---|---|---|---|
| Managerial | Leadership / Policy | Risk management decisions, governance documentation, and organizational security policy | Risk assessments, Acceptable Use Policy (AUP), security awareness program charters, gap analysis, vendor risk management policy |
| Operational | People / Processes | Day-to-day human actions and procedures that maintain the security posture | Security awareness training, background checks, incident response drills, change management procedures, patch management workflows |
| Technical | Hardware / Software | Automated or technology-enforced mechanisms that protect systems and data | Firewalls, encryption, intrusion detection systems (IDS), multi-factor authentication (MFA), access control lists (ACLs), antivirus, SIEM |
| Physical | Environment / Barriers | Tangible safeguards that protect facilities, hardware, and personnel from physical threats | Badge readers, biometric door locks, security guards, fencing, bollards, CCTV cameras, cable locks, server room cages |
Managerial controls exist at the governance layer. They establish what the organization's security program looks like and provide the authority for all other controls. Without strong managerial controls, operational and technical controls lack direction and accountability.
Operational controls are the human side of security. They are only as effective as the people executing them — which is why training, awareness, and well-documented procedures are critical. Social engineering attacks frequently succeed because operational controls are weak or inconsistently applied.
Six roles a control plays: the timing and manner in which it acts
While categories describe who implements a control, functional types describe what the control does when a threat arrives. A single control can serve multiple functional types simultaneously — a security camera is both deterrent (visible) and detective (records events).
Stops a security event from occurring. This is the most proactive functional type — the goal is to block the threat before any damage occurs.
Identifies and records a security event after it occurs or while it is occurring. Detective controls cannot stop an attack but provide the visibility needed to respond.
Reduces the damage caused by an incident and restores the system to normal operation. Corrective controls engage after an attack has been detected.
Discourages a threat actor from attempting an attack by signaling that consequences exist. Deterrents target the attacker's decision-making before any action is taken.
Directs users toward secure behaviors through required actions, policies, and documented standards. These controls guide what people should do rather than enforcing it automatically.
Substitutes for a primary control when that control cannot be implemented. A compensating control must provide equivalent or better risk reduction and is documented in a Plan of Action & Milestones (POA&M).
Drag each scenario into the correct Security Control Category
Select a breach scenario — identify the CIA violation and recommended control type
Which CIA property was violated? What control type should be deployed?
Which CIA property was violated? What control type should be deployed?
Which CIA property was violated? What control type should be deployed?
Which CIA property was violated? What control type should be deployed?
Select the best answer for each question, then submit for graded feedback