Every so often, people search for the term: Information Security. And every so often, what do they find?
And so this has become my mission to hopefully ease up what Information Security means in a non-technical manner. So, us normal users can better incorporate it in what we do whether at work or at home.
How changes affect security
With all these breakthroughs, however, comes the proportionally increasing danger. When before we only need to worry about physical safety locks deteriorating, now, in addition to the first, we also need to worry about storage media, access control, backup and so on and so forth. The complexities of these so-called protection has been increasing exponentially. This is in part because of the technological advancement mentioned earlier. The people who commit fraud, theft, sabotage, and all other criminal acts, have also improved their methods. One might want to think that we were better off staying in the stone age...
Awareness of the dangers
A practical example of this is when, us, users think that there's a very slim chance that we can be infected by a computer virus. It is probably because we are the only ones using the computer (or we are just lazy). So we skip installing or updating our anti-virus due to the hassle one must go (this hassle only takes a couple of minutes, by the way). And when we are infected, we go through several hours and spend money in order to remove the virus.
This is what I call firefighting. It is the total opposite of prevention methods.
Information Security in a Nutshell
Information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction.
It means protecting by preventing. The following steps are very general, but it may give us a clear understanding on what needs to be done and how information security runs its gears:
- Identify what needs protecting.
- Prioritize the assets by giving it value.
- Identify the dangers (risks) surrounding that asset.
- Coming up with a plan to prevent those dangers from happening.
- Implement those prevention plans.
- Measure the effectiveness of those prevention methods by using international best practices.
- Do it all over again.
My Own Conclusion
Most people think information security came from a purely technical stand point. That it is purely for technology since we're talking about the security of information and information systems. That may be a part of it, albeit a very small part. However, what we need to understand is that information security is not only I.T.'s responsibility. It is for everyone, technical or non-technical alike. It was suppose to have been practiced together with the advancement of technology (but only the techies did that). Then probably we wouldn't have been cramming to study it in one sitting. Like what we are doing now with this page/lens.
This may be a lot to take in. The whole concept of information security is vast (yet simple) so I will try to break it down into small parts that we can chew easily.
But that is for another article...
Need to know more?
Continue reading on in this article...-
Getting Down with Information Assets
-
The answer can be simple if your users are educated properly. Yet it can also be confusing when there is not enough knowledge from the start. This article aims to bridge that gap and hopefully provide guidance to both users and those who are just sta...
-
What are the elements of Information Security?
-
In order to implement an effective Information Security Management System (ISMS), it needs to be divided into major elements in order to have an organized and focused area. These elements, although interconnected, can be taken as separate parts and i...
Usefulness Survey
Vote now. Help me know if this article is useful.
InfoSec News
- Art of Information Security ยป Add Some Architecture to RSA 2010
- This year I am especially excited as I am leading a major Information Security infrastructure initiative that involves the complete build out of the Information Security stack for a new company (actually a $2.4B spin-off). ...
- IT@Intel Blog: Whitepaper: Prioritizing Information Security Risks ...
- Intel IT has developed a threat agent risk assessment (TARA) methodology that distills the immense number of possible information security attacks into a digest of only those exposures most likely to occur. ...
- Information Security Manager – CISSP, ISO 27001 – UK ...
- Reporting to the Head of Delivery you will develop, enhance and maintain the company's Information Security Policy to prevent breaches and you will produce, maintain and monitor adherence to IT Information Security standards, ...
- The Edcomm Group Banker's Academy Launches Information Security ...
- New York, NY, January 06, 2010 -- The Edcomm Group Banker's Academy has recently launched its Information Security training program for individuals looking to begin or advance their career in the financial services industry. ...
Get Started with Information Security
Tell me what you think
Share your thoughts and ideas about Information Security. You can also ask questions if you want.
-
Reply
- anjang anjang Sep 16, 2009 @ 10:07 am
- Hi junyap,
Nice info. In short information security is about confidentiality, integrity and availability.
-
Reply
- Homestyle-decors Homestyle-decors Apr 20, 2009 @ 10:46 pm
- Great Lens! Congratz
by 3 people |





