Understanding Information Security

1 - I can do better 2 - Jury's out 3 - Pretty darn good 4 - Splendiferous 5 - Awesometastic by 3 people | Log in to rate

Ranked #17,870 in How-To, #190,757 overall

Every so often, people search for the term: Information Security. And every so often, what do they find?

Searching Google, I found the top 10 results about Information Security are either purely technical in nature or a job description or about a company's security initiative. This frustrates me as one of the most important focus of information security is awareness not only to technical people; but to everyday users as well.

And so this has become my mission to hopefully ease up what Information Security means in a non-technical manner. So, us normal users can better incorporate it in what we do whether at work or at home.

How changes affect security 

Everyday, we see a rapid growth in technological advancement.We stand witness to the evolution of computers, devices, processes, software, the internet and many more. Numerous businesses are overhauling their processes in order to adapt to this advancement. People, in all ages, are also trying to learn what they can as much as possible. It is truly an amazing and dizzying thought to comprehend.

With all these breakthroughs, however, comes the proportionally increasing danger. When before we only need to worry about physical safety locks deteriorating, now, in addition to the first, we also need to worry about storage media, access control, backup and so on and so forth. The complexities of these so-called protection has been increasing exponentially. This is in part because of the technological advancement mentioned earlier. The people who commit fraud, theft, sabotage, and all other criminal acts, have also improved their methods. One might want to think that we were better off staying in the stone age...

Awareness of the dangers 

When we analyze the dangers stated, we also gain an understanding on how to prevent it. That is the concept of information security. It revolves around the concept of prevention methods. More often than not, businesses, organizations and individuals, all wait for something to happen; THEN we put our efforts into protecting something that has already been damaged.

A practical example of this is when, us, users think that there's a very slim chance that we can be infected by a computer virus. It is probably because we are the only ones using the computer (or we are just lazy). So we skip installing or updating our anti-virus due to the hassle one must go (this hassle only takes a couple of minutes, by the way). And when we are infected, we go through several hours and spend money in order to remove the virus.

This is what I call firefighting. It is the total opposite of prevention methods.

Information Security in a Nutshell 

In the words of bestfriend, Wikipedia:

Information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction.

It means protecting by preventing. The following steps are very general, but it may give us a clear understanding on what needs to be done and how information security runs its gears:

  • Identify what needs protecting.

  • Prioritize the assets by giving it value.

  • Identify the dangers (risks) surrounding that asset.

  • Coming up with a plan to prevent those dangers from happening.

  • Implement those prevention plans.

  • Measure the effectiveness of those prevention methods by using international best practices.

  • Do it all over again.

My Own Conclusion 

Now what I said may be oversimplifying things. And that may be true since the world has too many different best practices in one certain field. However, one thing stands constant: that there are best practices.

Most people think information security came from a purely technical stand point. That it is purely for technology since we're talking about the security of information and information systems. That may be a part of it, albeit a very small part. However, what we need to understand is that information security is not only I.T.'s responsibility. It is for everyone, technical or non-technical alike. It was suppose to have been practiced together with the advancement of technology (but only the techies did that). Then probably we wouldn't have been cramming to study it in one sitting. Like what we are doing now with this page/lens.

This may be a lot to take in. The whole concept of information security is vast (yet simple) so I will try to break it down into small parts that we can chew easily.

But that is for another article...

Need to know more? 

Continue reading on in this article...

Usefulness Survey 

Vote now. Help me know if this article is useful.

Loading poll. Please Wait...

InfoSec News 

Here are the latest news on Information Security
Art of Information Security ยป Add Some Architecture to RSA 2010
This year I am especially excited as I am leading a major Information Security infrastructure initiative that involves the complete build out of the Information Security stack for a new company (actually a $2.4B spin-off). ...
IT@Intel Blog: Whitepaper: Prioritizing Information Security Risks ...
Intel IT has developed a threat agent risk assessment (TARA) methodology that distills the immense number of possible information security attacks into a digest of only those exposures most likely to occur. ...
Information Security Manager – CISSP, ISO 27001 – UK ...
Reporting to the Head of Delivery you will develop, enhance and maintain the company's Information Security Policy to prevent breaches and you will produce, maintain and monitor adherence to IT Information Security standards, ...
The Edcomm Group Banker's Academy Launches Information Security ...
New York, NY, January 06, 2010 -- The Edcomm Group Banker's Academy has recently launched its Information Security training program for individuals looking to begin or advance their career in the financial services industry. ...

Get Started with Information Security 

Here are some books in order for you to get started with Information Security and how to put up an Information Security Management System.

Principles of Information Security

Tell me what you think 

Share your thoughts and ideas about Information Security. You can also ask questions if you want.

submit

by junyap

Thoughts and opinions are always interesting. It shows each person's unique ability to perceive or see things and or events the way they want to see i... (more)

Explore related pages

Create a Lens!