Information Security
On this page
3.1 Information Security
Suggested retrieval lesson: 20–30 minutes.
Recall first
- Define confidentiality, integrity, and availability (CIA).
- Which CIA property is damaged when an unauthorized employee edits a salary record?
- Is privacy identical to security? Explain.
Commit before reading.
What information security protects
Information security protects information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction so that organizational operations and people remain protected. It is a risk-management discipline involving people, processes, technology, and physical environments—not only antivirus software. NIST SP 800-53 describes security and privacy controls as protecting operations, assets, individuals, and organizations from diverse threats and risks. NIST SP 800-53 Rev. 5
CIA triad
- Confidentiality: information is not disclosed to unauthorized people, processes, or systems. Controls include least privilege, encryption, and access reviews.
- Integrity: information and systems are accurate, complete, authentic, and not improperly altered or destroyed. Controls include input validation, hashes/signatures, separation of duties, and audit trails.
- Availability: authorized users can access systems and information when needed. Controls include redundancy, backups, capacity planning, patching, and recovery procedures.
Use the affected property, not the attack name, as the answer. A ransomware event can threaten availability; if data are altered it also threatens integrity; if stolen it threatens confidentiality.
Security also supports authenticity (an entity or message is genuine), accountability (actions can be traced to responsible identities), and sometimes non-repudiation (evidence makes denial of an action difficult). These strengthen CIA but are not replacements for it.
Security, privacy, and assurance
Security controls unauthorized or harmful actions. Privacy concerns appropriate collection, use, disclosure, retention, and individual rights over personal information. Strong security is necessary for privacy but cannot make an unjustified collection practice ethical. A system can securely retain too much data for too long. Good security starts with asset identification, business impact, legal/ethical requirements, risk assessment, layered controls, monitoring, incident response, and recovery.
NIST CSF 2.0 organizes cybersecurity outcomes into Govern, Identify, Protect, Detect, Respond, Recover. It is a flexible framework, not a prescriptive checklist; organizations select practices according to risk. NIST CSF 2.0
Worked example: payroll system
Confidentiality means only authorized HR/payroll staff see salary data. Integrity means an approved change to a bank account is accurate, authorized, and logged. Availability means payroll can run on payday even after a server failure. Privacy additionally asks whether the employer collected only necessary data, explained its use, limited retention, and gave appropriate rights. One control rarely protects all three: encryption helps confidentiality, validation and approval help integrity, and tested backups help availability.
Exercise — reveal after committing
A database remains online during an attack, but attackers copy employee tax records and modify several bank-account numbers. Which CIA properties are affected, and name one control for each.
Revealed answer: Confidentiality is affected by copying records; integrity by modifying bank details. Availability is not necessarily affected because the database stayed online. Examples: access controls/encryption and exfiltration monitoring for confidentiality; change approval, validation, immutable logs, and reconciliation for integrity.
Exam lens
- Write CIA as confidentiality, integrity, availability, with definition and example.
- Do not equate privacy with confidentiality: privacy governs appropriate personal-data practices; confidentiality is unauthorized disclosure protection.
- Security is broader than technology: include policy, people, physical safeguards, monitoring, response, and recovery.
- Distinguish a framework (NIST CSF) from a control catalog (NIST SP 800-53).
Rapid revision checklist
- Define CIA and give two controls for each.
- Distinguish authenticity, accountability, and privacy.
- Explain why one incident may affect multiple CIA properties.
- Recall NIST CSF’s six functions.
- State the security lifecycle: identify, protect, detect, respond, recover.
Key takeaways
- Information security manages risks to information and systems.
- CIA is the core exam model; use concrete controls and examples.
- Privacy and security overlap but answer different questions.
- Security requires governance, prevention, detection, response, and recovery.
Sources
- Rainer & Prince, Management Information Systems (Wiley) — textbook exam framing for information security.
- Laudon & Laudon, Management Information Systems: Managing the Digital Firm, 10th ed. — textbook exam framing for security, privacy, and controls.
- Boddy & Boonstra, Managing Information Systems: Strategy and Organization — textbook exam framing.
- NIST, Cybersecurity Framework 2.0 — supplement for risk-management functions.
- NIST, SP 800-53 Rev. 5 — supplement for security/privacy control families.