Question

Define the core concepts of information security. Why are these concepts so important to Information Security...

Define the core concepts of information security. Why are these concepts so important to Information Security Governance and Risk Management?  
0 0
Add a comment Improve this question Transcribed image text
Answer #1

Ans) Today we have easy access to information available all around the globe. This is possible through internet which can be accessed via mobile phones, laptop, smart tv and many more.

However there is always some risk associated with these information. Our information can be stolen, altered or misused by intruders over the network. Hence the role of information security becomes much important for the users.

The concept of information security is based on CIA triad where C stands for confidentiality, I stands for integrity and A stands for availability.

Confidentiality:

When your information is available to someone who is an unauthorized user then it is said to be loss of confidentiality. While making online transactions our sensitive information such as card number, cvv number and atm pin must be protected to achieve confidentiality. Hence it is always advisable to use https server rather than http server which is more secure than http.

Integrity:

Integrity is violated when an unauthorized user make changes to your sensitive information. Integrity can only be achieved if your information remains unaltered while storing or transmission. For eg: It is always advisable to properly lock your system while not using it, always use strong password for your device.

Availability:

Inaccessibility to your own information leads to loss of availability. Users don’t have access to their own information. The most common example can be ransomware attack which prevented users from accessing their own files.

The most affected organizations which are vulnerable to cyber attack are banks, financial companies etc. another important term related to cyber security are authentication and authorization.

Authentication means providing access to data to valid users and authorization mean rights available to users to manipulate data.

ii)The information security governance and risk management focuses  on identifying organization’s sensitive information assets and setting standards,policies,guidelines ensuring confidentiality integrity and availability. Management tools are used to identify risk factors   associated to cyber attack, threats and and taking appropriate measures to protect them.

Add a comment
Know the answer?
Add Answer to:
Define the core concepts of information security. Why are these concepts so important to Information Security...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT