High-Level Information Security Concepts

When developing your information security program, some important concepts to drive your processes are confidentiality, integrity, and availability (CIA), least privilege, and speed versus control. These concepts span the people, process, and technology components of your program. You should consider these principles both when developing your strategy and during routine management.

CIA is an important concept that you need to consider, especially when establishing your overall strategy. Confidentiality ensures that your program protects sensitive information from unauthorized access or disclosure. Confidentiality includes the use of transmission encryption (such as the use of SSL on web sites to enter ...

Get Executive Guide to Information Security, The: Threats, Challenges, and Solutions now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.