Important Security Concepts
Information security professionals focus on three fundamental areas of protection:
- Confidentiality
- Integrity
- Availability
Without one of these areas, an organization is more vulnerable to harm or damage and is exposed to higher information security risks. The CISSP must plan and design good security governance using these three concepts.
Managing security is like the support of a three-legged stool, as shown in Figure 1.1. If one area of security falters, the entire organization is vulnerable to data theft, malware infections, and ransomware attacks. This places the entire firm at risk of going out of business, causing potentially thousands of people to lose their jobs.
Figure 1.1: The CIA three-legged stool
For example, hospitals such as St. Lawrence Health System in New York suffered major ransomware attacks because their staff clicked on links within emails, which is also known as phishing (you can...