Vulnerabilities and Threats in Terms of CIA Under ISO 27001, ISO 27002, and ISO 27005

Introduction

Information Security Management Systems (ISMS), as defined by ISO/IEC 27001:2022, are designed to preserve the Confidentiality, Integrity, and Availability (CIA) of information through a structured risk management process. Vulnerabilities and threats directly affect these three core dimensions and, if unmanaged, can lead to severe breaches of regulatory obligations, including those under GDPR. ISO/IEC 27005 provides detailed guidance on identifying and assessing risks, while ISO/IEC 27002 defines specific control measures to mitigate them.

1. Confidentiality

Confidentiality ensures that information is only accessible to those authorized.

Threats

· External cyber-attacks (e.g., phishing, malware).

· Insider threats (misuse of access).

· Eavesdropping or interception of communications.

Vulnerabilities

· Weak authentication mechanisms.

· Poor encryption practices.

· Uncontrolled sharing of credentials.

Example

A poorly configured access control system (vulnerability) exploited by a malicious insider (threat) can result in unauthorized disclosure of personal identifiable information (PII), violating GDPR Article 32.

2. Integrity

Integrity guarantees the accuracy and completeness of data and systems.

Threats

· Unauthorized modifications of records.

· Injection attacks or malware altering data.

· Errors introduced by misconfigured systems.

Vulnerabilities

· Lack of change control procedures.

· Absence of system validation.

· Inadequate audit logging.

Example

A vulnerability in patch management could allow a threat actor to exploit outdated software, leading to data corruption or manipulation of financial records, undermining GDPR's accuracy principle (Article 5(1)(d)).

3. Availability

Availability ensures information is accessible when required by authorized users.

Threats

· Distributed Denial of Service (DDoS) attacks.

· Natural disasters or utility failures.

· Ransomware locking systems.

Vulnerabilities

· Single points of failure.

· Lack of backup and redundancy.

· Insufficient disaster recovery planning.

Example

A data centre with no backup power (vulnerability) impacted by a regional power outage (threat) may result in prolonged unavailability of critical health data, impacting GDPR's requirement for timely access by data subjects.

4. The Role of Risk Assessment (ISO/IEC 27005)

ISO/IEC 27005 emphasizes that vulnerabilities and threats must be considered in the risk assessment process. Organizations should:

1. Identify risks related to loss of CIA.

2. Analyse likelihood and impact of threat exploitation.

3. Evaluate risks against acceptance criteria.

4. Treat risks with controls defined in ISO/IEC 27002 and Annex A of ISO/IEC 27001.

5. Control Framework (ISO/IEC 27002 and Annex A of ISO/IEC 27001)

ISO/IEC 27002 specifies practical controls aligned with CIA, such as:

· Confidentiality: Encryption (A.8.24), Access Rights Management (A.5.18).

· Integrity: Secure coding (A.8.28), Logging and Monitoring (A.8.15-16).

· Availability: Backup (A.8.13), Redundancy (A.8.14), Business Continuity (A.5.30).

Together, these controls directly address vulnerabilities and mitigate threats to information security.

Conclusion

The CIA triad forms the backbone of ISO/IEC 27001-compliant ISMS. Threats exploit vulnerabilities, potentially compromising confidentiality, integrity, or availability of information assets. By applying ISO/IEC 27005 risk assessment methods and implementing ISO/IEC 27002 controls, organizations can not only meet regulatory expectations under GDPR but also foster digital trust and resilience.