What is information security?

What is information security?

This is the first instance in a series of articles covering the basics about information security. What could be more basic to begin with than talking about information security in general? Let's have a look at the official definition from ISO 27000:2018 first.

"Information security ensures the confidentiality, availability and integrity of information."


Information is essential for the success and continuity of most organizations. This is why information is considered as an asset that requires rigid protection. Information can be stored in many forms.

  • digital form (e.g. data in a database)
  • material form (e.g information printed on paper)
  • unrepresented form?(e.g knowledge of the organisation)

Security Objectives

Organizations are increasingly depending on the confidentiality, integrity and availability of their information and the related information systems. These security objectives are often referred to as the CIA triad.

No alt text provided for this image


Confidentiality

Keeping information confidential is all about preventing unauthorised people from gaining access to it. This implies that organizations need to classify their information which allows them to define access and protection levels that have to be enforced by implementing controls like physical security or cryptography.

Integrity

Integrity is the second component of the CIA triad. Information has to be protected from unauthorized modification, so people can rely on the integrity of the information. This is why changes need to be tracked, so the damage of in case of a mistake can be reversed.

Availability

Because of the importance of information for the ongoing operations of most organizations, information has to be available. To support that security objective organizations require backups and technical controls to ensure the availability of information systems

?? Ready to shake up your routine with a newsletter subscription that can help you crush your learning objectives? Give it a try and subscribe and to InfoSec Insights, your weekly source of educational content for everything information security related.

Raj Sundar

Seasoned Global Information Security & Privacy Risk Governance, Strategy and Transformation leader | MBA | CISSP | CCSFP | CCSK | CIPT | CRISC | PMP

3 年

Hi Aron, Congrats on this new knowledge-sharing initiative, and Thanks a lot for the invite.

回复
Animesh Kumar Mishra

AI & ML Product Security

3 年

Hi Aron Lange, thank you for the subscription invitation. I remember when I was a fresher and new to InfoSec industry, I used to look for bite size articles to help me get started. I am sure folks from all fields will be able to find this helpful (either from educational or awareness perspective)! Great work!

Lok Yi Lo

PhD Candidate (Cybersecurity), CISSP, CISA, CISM, ACCA

3 年

Good work, Aron Lange.

回复
David Blank

Business Psychology Student @ Hochschule Neu-Ulm

3 年

Hi Aron, thanks for the subscription invitation and congrats on the release of your article!

回复
Carlos Alberto Concei??o

Encarregado de Prote??o de Dados Pessoais (DPO) | Compliance Officer | Privacidade de Dados | Seguran?a da Informa??o | Gest?o e Melhoria de Processos

3 年

Congratulations Aron Lange!!

要查看或添加评论,请登录

Aron Lange的更多文章

  • 4 New and Free Resources by NIST

    4 New and Free Resources by NIST

    I haven't used my LinkedIn Newsletter in a while. But, due to popular request, I'm giving it another shot.

    1 条评论
  • The Top 5 Newsletters of 2023

    The Top 5 Newsletters of 2023

    In 2023, I sent out 25 newsletters about Governance, Risk and Compliance topics. Here are the most popular editions of…

  • Introducing LearnGRC

    Introducing LearnGRC

    Dear Readers, when I started this newsletter, I wanted to focus on demystifying the world of information security…

    16 条评论
  • My Journey to Becoming a Certified Information Security Manager (CISM)

    My Journey to Becoming a Certified Information Security Manager (CISM)

    Dear Community, I have some thrilling news to share with you! I have decided to embark on a journey towards becoming a…

    4 条评论
  • The All-New Resource Center

    The All-New Resource Center

    Dear Readers, I am thrilled to announce the release of Resource Center! As security professionals, we are always on the…

    15 条评论
  • Cybersecurity Made Easy: Free and Low-Cost Courses

    Cybersecurity Made Easy: Free and Low-Cost Courses

    In today's world, cybersecurity is becoming more and more critical. With the rise of cyberattacks, the need for…

    8 条评论
  • Free Resources for Security and GRC

    Free Resources for Security and GRC

    Here is my list of free resources that will help you to break into GRC and information security. By the way, this is…

    10 条评论
  • Running an audit programme

    Running an audit programme

    Running an internal audit programme is a mandatory requirement within all management systems that seek to be certified…

    1 条评论
  • The new ISO 27002:2022

    The new ISO 27002:2022

    For the first time since 2013 a new revision of ISO 27002 has been published. In case you think thats too good to be…

    12 条评论
  • Security Controls

    Security Controls

    In this edition of InfoSec Insights we are going to talk about controls. You will learn what controls are used for and…

    2 条评论

社区洞察

其他会员也浏览了