Thursday, June 10, 2010

What is Security in the context of Information Assurance?

This means different things to different people.  The first and foremost principle is the protection of human life.  After that, it is in the eye of the beholder.  To me, we have the foundations of Confidentiality, Integrity and Availability.  This was known as the CIA triad but has been changed to the AIC triad due to the similarity in the acronym of a US Intelligence agency.  If you want information from them, click here. 

Think of security more as a framework.  It cannot impede the flow of business.  It must be there to protect the business and individuals.  Where do you begin when you want to think about security?  First, there are some basic questions you should as yourself.

  • Do I have anything that needs protecting?

If the answer is no, then you have nothing to worry about and you can go off being the free spirit that you always dreamed about.  Unfortunately for the rest of us, we do have something we need to protect.  This can be our identity, money, home, business,  data and most importantly, the ones we love.  This world is a very nice place but there are some very bad things that go on in it.  Go out there and start thinking of all of the things that need protection.  It can become mind boggling and could easily overwhelm you.  Next start thinking of the value of those items you need to protect.  Are some of those things valuable in terms of monetary value, intellectual property, proprietary information or just sentimental.  How could those items be replaced?  This is the process of valuation.  Some values are tangible and some are intangible. 

More to come…

No comments:

Post a Comment