Good security rests on a handful of durable ideas. Technologies change, threats evolve, but a small set of principles continues to guide how systems should be designed, defended, and operated. This category gathers those principles so readers have a shared vocabulary for everything that follows. It anchors the Foundation pillar because these concepts underpin nearly every control, policy, and decision in the field.
The topics below define the essentials.
The CIA triad describes the three goals of confidentiality, integrity, and availability that most controls serve.
Defense in depth layers protections so that no single failure exposes the whole system.
Least privilege grants each user and process only the access it genuinely needs.
Zero trust assumes no implicit trust and verifies every request.
Accountability ensures actions can be traced to a responsible party.
Authentication and authorization establish who someone is and what they are allowed to do.
Security by design builds protection in from the start rather than bolting it on later.
Minimization reduces the data, access, and attack surface to only what is required.