/*
Customise Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.

/*]]>*/

Information Security

February 28, 2018

You are here:
< Back

Here’s a quick information security overview…

Definition

The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.
SOURCE: SP 800-37; SP 800-53; SP 800-53A; SP 800-18; SP 80060; CNSSI-4009; FIPS 200; FIPS 199; 44 U.S.C., Sec. 3542

Protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide—

1) integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;
2) confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and
3) availability, which means ensuring timely and reliable access to and use of information.
SOURCE: SP 800-66; 44 U.S.C., Sec 3541

Everyday Overview

Information security, or InfoSec, is the practice of protecting information from unauthorized access, misuse, or destructionIt includes policies, procedures, and tools to protect data in all forms, including physical and digital. 

Goals 
  • ConfidentialityProtecting the secrecy of information
  • IntegrityProtecting the accuracy and completeness of information
  • AvailabilityProtecting the accessibility of information
Types of information security
Information security policies 
  • Establish a general approach to information security
  • Document security measures and user access control policies
  • Ensure that only authorized users can access sensitive systems and information
  • Monitor networks for security breaches
  • Investigate security breaches
  • Use and maintain software, such as firewalls and data encryption programs
  • Check for vulnerabilities in computer and network systems

See Microsoft Definition