Security addresses protection against unauthorized access, misuse, damage and other security events. Typical areas include access management, monitoring, vulnerability management, incident response, risk assessment and change management.
Availability addresses whether systems and information are accessible and operational in accordance with commitments. Typical areas include monitoring, backups, disaster recovery, business continuity and capacity management.
Processing Integrity addresses whether system processing is complete, valid, accurate, timely and authorized.
Confidentiality addresses protection of information designated as confidential, including classification, access restrictions, encryption, retention and disposal.
Privacy addresses the collection, use, retention, disclosure and disposal of personal information in accordance with privacy commitments.