INFORMATION SECURITY

INFORMATION SECURITY

Information Security is not only about securing information from unauthorized access. Information Security is basically the practice of preventing unauthorized access, use, disclosure, disruption, modification, inspection, recording or destruction of information. Information can be physical or electronic one. Information can be anything like Your details or we can say your profile on social media, your data in mobile phone, your biometrics etc. Thus Information Security spans so many research areas like Cryptography, Mobile Computing, Cyber Forensics, Online Social Media etc.

Information Security programs are build around 3 objectives, commonly known as CIA – Confidentiality, Integrity, Availability.

Confidentiality – means information is not disclosed to unauthorized individuals, entities and process.

Integrity – means maintaining accuracy and completeness of data. This means data cannot be edited in an unauthorized way.

Availability – means information must be available when needed.

Denial of service attack is one of the factor that can hamper the availability of information.

Apart from this there is one more principle that governs information security programs. This is Non repudiation.

Non repudiation – means one party cannot deny receiving a message or a transaction nor can the other party deny sending a message or a transaction.

Authenticity – means verifying that users are who they say they are and that each input arriving at destination is from a trusted source .This principle if followed guarantees the valid and genuine message received from a trusted source through a valid transmission.

Accountability – means that it should be possible to trace actions of an entity uniquely to that entity.

At the core of Information Security is Information Assurance, which means the act of maintaining CIA of information, ensuring that information is not compromised in any way when critical issues arise. These issues are not limited to natural disasters, computer/server malfunctions etc.

?Thus, the field of information security has grown and evolved significantly in recent years. It offers many areas for specialization, including securing networks and allied infrastructure, securing applications and databases, security testing, information systems auditing, business continuity planning etc.

BY

DARSHAN.S

要查看或添加评论,请登录

Darshan(?????) S的更多文章

社区洞察

其他会员也浏览了