Fundamentals of information security
Confidentiality, integrity, and availability (collectively known as CIA) are the fundamental pillars of information security. It is an absolute requirement for the risk manager to understand and account for these to ensure all decisions are risk-based and derived with these three security pillars in mind. Let’s look at these pillars in detail:
- Confidentiality: Confidentiality ensures that information is only accessible to authorized individuals. Unauthorized access to sensitive information can lead to incidents such as identity theft, fraud, or damage to an individual’s or organization’s reputation. Confidentiality can be ensured through technical and administrative controls such as encryption, masking, access control, training, and other similar controls.
Two important principles are related to maintaining confidentiality, as follows:
- The need-to-know principle ensures that individuals should be given...