Skip to main content
“Anyone who talks about sovereignty must also talk about CIA!” – Digital PLM/ALM sovereignty
Digital sovereignty

Measuring sovereignty: what the CIA triad contributes

Digital PLM/ALM sovereignty as an end in itself isn't helpful. The CIA triad from information security offers a grid for rating an IT solution.

Automatically translated from German · Read the original

Julian Weyer
Julian Weyer March 4, 2026 · 3 min read
Digital sovereignty ·Digital sovereignty ·PLM ·3 min read

Digital PLM/ALM sovereignty as an end in itself? I don’t think that’s particularly smart. Not because I dislike intrinsic motivation, quite the opposite. But I see the danger of being dazzled, and of supposedly sovereign solutions turning out not to be what they claim to be: sovereign-washing.

In information security, people often talk about protection goals. The most important of these are confidentiality, integrity and availability, in short: the CIA triad.

The protection goals themselves are nothing new. But in the context of digital sovereignty, too, they are well suited to specifying or rating the degree of sovereignty of an IT solution.

Confidentiality

How important is it to the company that corporate data and intellectual property really stay confidential? How well must this data be protected against possible state-organized leakage to third countries?

Integrity

How strongly must the data be protected against undetected manipulation or sabotage?

Availability

How reliable is the continuous availability of the PLM solution and the data in it? Or could data and business processes in the chosen PLM/ALM solution be at risk for geopolitical reasons?

In an earlier post in this series, I already argued that absolute sovereignty cannot exist in a world built on division of labor. Sovereignty is not an end in itself. That makes it all the more important to be clear about how much sovereignty is wanted, and whether it should be ensured through organizational, architectural or technical measures.

After all, these protection goals can be achieved in different ways: architecturally, by choosing vendors and service providers under a friendly jurisdiction; organizationally, through suitable contract design; or technically, through encryption and digital signatures.

If a PLM architecture is to be sovereign, it must therefore be examined in at least these three dimensions, in order to decide whether its degree of sovereignty fits your own company strategy.

Conclusion

The CIA triad from information security provides a proven grid for assessing sovereignty in concrete rather than abstract terms: confidentiality, integrity and availability can be addressed architecturally, organizationally or technically, but only if you know beforehand how much sovereignty is needed at all.