What is information security?
Information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification or destruction by ensuring the following security objectives:
Confidentiality
Makes sure that data remains private and confidential. It should not be viewed by unauthorized people through any means
Information disclosure is a cyber-attack that reads all emails sent to/by the victim by eavesdropping into the communication network; hence, compromising confidentiality
Integrity
Assures that data is protected from accidental or any deliberate modification
Tampering is a cyber-attack where attacker modifies an incoming email before it reaches the intended recipient. Receiver would not know that the received message was modified; hence, compromising integrity
Availability
Ensures timely and reliable access to information and its use
Denial of service is a cyber-attack where the website becomes unavailable for legitimate users, restricting the availability of the website
Confidentiality, Integrity and Availability (CIA) are the objectives of information security. All protection mechanisms aim to protect one or more of these objectives. Sometimes, an alternate term Disclosure, Alteration and Denial (DAD, in negative form) is used to refer to these objectives.
Comments
Post a Comment