DICP: the four information security criteria

Availability, integrity, confidentiality, proof: definitions, scales of need and a step-by-step assessment example.

· 7 min read
Illustration: four glass tiles in a row, the last one orange

DICP is the French acronym for the four information security criteria: Availability, Integrity, Confidentiality and Proof. Assessing the DICP needs of a piece of information or a process means rating on a scale how demanding each of these criteria is. This profile then serves as the basis for risk analysis and the choice of security controls.

01

What does DICP mean? The four criteria defined

The DICP criteria answer a simple question: what would be serious for this information? That it becomes inaccessible, that it is wrong, that it falls into the wrong hands, or that nobody can prove who changed it. The first three criteria are defined by the ISO/IEC 27000 vocabulary standard; the fourth is a widespread French practice.

D for Availability (Disponibilité)

Availability is the property of information or a service being accessible and usable when an authorised person needs it. It is often expressed as a maximum tolerable outage time: a few days for an intranet, less than one hour for an emergency dispatch system. This criterion ties in directly with business continuity.

I for Integrity

Integrity guarantees that information is accurate and complete, and has not been changed without authorisation, whether maliciously or by mistake. A transfer whose bank details have been altered, a modified dosage in a medical record or a changed price on an online shop are all breaches of integrity.

C for Confidentiality

Confidentiality ensures that information is only accessible to authorised people, entities or processes. It is broken down into distribution levels: public, internal, restricted, highly restricted. It is the most intuitive criterion, but rarely the only one at stake.

P for Proof (or traceability)

Proof is the ability to establish who did what and when, and to demonstrate it, including to a third party. It covers traceability (logs), accountability (linking an action to a person) and non-repudiation (preventing someone from denying an action). The term DICT is also used, with T for traceability; “proof” is broader, because a trace that is neither protected nor timestamped proves very little.

02

DICP, DIC, DICT and the CIA triad: what are the differences?

These acronyms refer to the same family of criteria, with broader or narrower coverage. The CIA triad (Confidentiality, Integrity, Availability) is the international reference, used by ISO and by the US NIST in its FIPS 199 standard. The GDPR refers to it too: its Article 32 requires the ability to ensure “the ongoing confidentiality, integrity, availability and resilience” of processing systems.

CIA triad The international baseline (ISO/IEC 27000, NIST)
  • C Confidentiality
  • I Integrity
  • A Availability
DICP French practice, adding proof
  1. DAvailability
  2. IIntegrity
  3. CConfidentiality
  4. PProoftraceability, accountability, non-repudiation
The CIA triad (Confidentiality, Integrity, Availability) matches the French DIC. DICP adds proof, which covers the traceability and accountability of actions.
AcronymCriteriaUse
CIAConfidentiality, integrity, availabilityInternational reference (ISO, NIST)
DICAvailability, integrity, confidentialityFrench equivalent of the CIA triad
DICTDIC + traceabilityAdds the retention of traces
DICPDIC + proofAdds accountability and the evidential value of traces
03

DICP scales of security needs

A DICP need only makes sense if it is rated on a common scale, defined before the assessment and identical across the organisation. ANSSI's EBIOS Risk Manager guide points out that the goal is not to find an absolute value but to position pieces of information relative to one another. Most organisations use four levels, which avoids the temptation of a “medium” in the middle. Here is an example scale, to be adapted to your context.

LevelAvailabilityIntegrityConfidentialityProof
1 · LowOutage of more than a week tolerableErrors toleratedPublicNo need
2 · MediumUp to 48 hoursErrors tolerated if detected and correctedInternalTechnical traces
3 · HighUp to 4 hoursAny alteration detected quicklyRestricted to a groupActions attributable to a person
4 · CriticalLess than one hourNo alteration toleratedHighly restricted, named individualsProof enforceable against a third party

Availability thresholds must match your activities: for a payroll service, a 48-hour outage mid-month goes unnoticed, but not the day before salaries are paid. Feel free to specify critical periods in the scale.

04

Example: assessing the DICP needs of an asset

Take the payroll data of a 300-employee company. The HR manager, who owns the information, answers four questions with the CISO, reasoning about the consequences of a breach rather than about the protections already in place.

  • Availability: 2. A two-day outage can be caught up, except the day before payroll, flagged as a critical period.
  • Integrity: 4. A changed bank detail diverts a salary; a wrong amount has social and legal consequences.
  • Confidentiality: 3. Salaries and social security numbers are personal data restricted to the HR department and the payroll provider.
  • Proof: 3. Every change to bank details or salaries must be attributable to a person, in case of fraud or inspection.

The resulting profile, D2 · I4 · C3 · P3, immediately shows where to focus: on integrity checks and on tracing changes to bank details, far more than on high availability. Try the assessor below with three example assets, then adjust the levels to see the typical controls change.

Asset assessed

Public pages presenting the company.

Availability
Outage tolerable for up to 48 hours Typical controls at this level Tested backups and recovery procedure
Integrity
Any alteration must be detected quickly Typical controls at this level Dual approval, consistency checks
Confidentiality
Public information Typical controls at this level No read restriction
Proof
No need for proof Typical controls at this level No dedicated logging
DICP profile D2 · I3 · C1 · P1
Highest need 3 · High
Example profiles only: actual levels depend on your context and must be validated by the business owner of the information.
05

From DICP to risk analysis and EBIOS RM

DICP does not measure a risk: it expresses a need. Risk appears when that need is combined with a threat and a likelihood. This is why the DICP assessment comes at the start of any risk analysis.

  • In EBIOS Risk Manager, workshop 1 identifies business assets (essential information and processes) and ranks them according to their security needs, such as availability, integrity or confidentiality. These needs guide the severity of feared events. Our risk analysis module supports the method.
  • With ISO 27005, DICP needs feed the consequence criteria used when analysing and evaluating risks.
  • For a security accreditation, the system's DICP profile justifies the level of the selected controls to the accrediting authority.

One decisive point of method: you assess the DICP of business assets (payroll, the patient record), and the supporting assets that carry them (server, application, supplier) inherit it. The result can then be shown in a risk matrix.

06

DICP assessment: five mistakes to avoid

  • Rating everything at the maximum. If everything is critical, nothing is: the security budget can no longer be prioritised.
  • Assessing the server rather than the information. The need comes from business use, not from technology.
  • Assessing without the business. The CISO facilitates, but the information owner knows the real consequences and validates.
  • Confusing need with existing protection. “It is already encrypted, so C1” is a misreading: the need remains C3 even if the control is in place.
  • Never reviewing. A new regulation, such as the French obligation for certified health data hosting, or a new use can change a need.

In Phinasoft, business assets and their security needs are entered in the risk analysis itself, with your own scales, and linked to scenarios and to the action plan. The risk analysis module invites business contributors into the analysis and guides them step by step. To see it applied to your own assets, you can request a demo.

Summary

01

Four criteria

DICP expresses what a piece of information must guarantee: be accessible when needed, accurate, restricted to the right people, and leave a reliable trace of actions.

02

A shared scale

Each criterion is rated on a four-level scale, defined in advance and common to the whole organisation, so that assets can be compared and controls sized accordingly.

03

The starting point for risk

The DICP profile of a business asset sets the severity of feared events in an ISO 27005 or EBIOS RM risk analysis. It is validated with the business, not alone.

Frequently asked questions

What does DICP stand for?

DICP is the French acronym for Availability (Disponibilité), Integrity, Confidentiality and Proof (Preuve). These are the four criteria used to express the security needs of a piece of information or a business process. Proof, sometimes replaced by traceability (DICT), is the ability to establish who did what and when.

What is the difference between DIC and DICP?

DIC covers only availability, integrity and confidentiality, the equivalent of the CIA triad. DICP adds proof, which matters whenever an action must be attributed to a person or demonstrated to a third party: financial transactions, medical records, signatures, regulatory checks.

How do you assess DICP needs?

First define a four-level scale for each criterion, with concrete thresholds (tolerable outage time, authorised audience). Then, for each piece of information or process, the business owner chooses the required level with the CISO's help, reasoning about the consequences of a breach rather than about existing controls.

What is the CIA triad?

The CIA triad (Confidentiality, Integrity, Availability) groups the three basic properties of information security, defined in particular by ISO/IEC 27000 and by the US NIST. It is the English-language equivalent of the French DIC. The GDPR also refers to these notions in its Article 32.

Is DICP used in EBIOS RM?

Yes, in a similar form. In workshop 1 of EBIOS Risk Manager, business assets are ranked according to their security needs, such as availability, integrity or confidentiality. These needs are then used to estimate the severity of feared events. ANSSI leaves the choice of criteria and scales open.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.