§ 3.1Module 3

Information Security

On this page

3.1 Information Security

Suggested retrieval lesson: 20–30 minutes.

Recall first

  1. Define confidentiality, integrity, and availability (CIA).
  2. Which CIA property is damaged when an unauthorized employee edits a salary record?
  3. Is privacy identical to security? Explain.

Commit before reading.

What information security protects

Information security protects information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction so that organizational operations and people remain protected. It is a risk-management discipline involving people, processes, technology, and physical environments—not only antivirus software. NIST SP 800-53 describes security and privacy controls as protecting operations, assets, individuals, and organizations from diverse threats and risks. NIST SP 800-53 Rev. 5

CIA triad

Use the affected property, not the attack name, as the answer. A ransomware event can threaten availability; if data are altered it also threatens integrity; if stolen it threatens confidentiality.

Security also supports authenticity (an entity or message is genuine), accountability (actions can be traced to responsible identities), and sometimes non-repudiation (evidence makes denial of an action difficult). These strengthen CIA but are not replacements for it.

Security, privacy, and assurance

Security controls unauthorized or harmful actions. Privacy concerns appropriate collection, use, disclosure, retention, and individual rights over personal information. Strong security is necessary for privacy but cannot make an unjustified collection practice ethical. A system can securely retain too much data for too long. Good security starts with asset identification, business impact, legal/ethical requirements, risk assessment, layered controls, monitoring, incident response, and recovery.

NIST CSF 2.0 organizes cybersecurity outcomes into Govern, Identify, Protect, Detect, Respond, Recover. It is a flexible framework, not a prescriptive checklist; organizations select practices according to risk. NIST CSF 2.0

Worked example: payroll system

Confidentiality means only authorized HR/payroll staff see salary data. Integrity means an approved change to a bank account is accurate, authorized, and logged. Availability means payroll can run on payday even after a server failure. Privacy additionally asks whether the employer collected only necessary data, explained its use, limited retention, and gave appropriate rights. One control rarely protects all three: encryption helps confidentiality, validation and approval help integrity, and tested backups help availability.

Exercise — reveal after committing

A database remains online during an attack, but attackers copy employee tax records and modify several bank-account numbers. Which CIA properties are affected, and name one control for each.

Revealed answer: Confidentiality is affected by copying records; integrity by modifying bank details. Availability is not necessarily affected because the database stayed online. Examples: access controls/encryption and exfiltration monitoring for confidentiality; change approval, validation, immutable logs, and reconciliation for integrity.

Exam lens

Rapid revision checklist

Key takeaways

  1. Information security manages risks to information and systems.
  2. CIA is the core exam model; use concrete controls and examples.
  3. Privacy and security overlap but answer different questions.
  4. Security requires governance, prevention, detection, response, and recovery.

Sources