chapter one

1 Security Concepts of Information Assurance

 

This chapter covers

  • Fundamental terms of cybersecurity
  • The CIA Triad
  • Data classification

Organizations create value by coordinating people, processes, and technology. Technology is part of what we refer to as infrastructure, which can be both physical and digital. Physical includes buildings, servers, or network equipment. Digital includes software and data.

As cybersecurity professionals, our goal is to protect the organization's infrastructure, processes, and people from disruptions caused by threats or adverse events. In other words, to do our job well, we need to understand the organizations we work with, map the relevant threats we need to protect against, and implement effective controls to mitigate them whilst maintaining business continuity.

This chapter defines basic cybersecurity concepts that professionals use regularly. First, we will define threats and vulnerabilities. Then, we will use the Confidentiality, Integrity, and Availability (CIA) model to analyze vulnerabilities and security controls. Finally, we will conclude with common data classifications based on value and sensitivity.

1.1 Fundamental Terms of Cybersecurity

1.1.1 Organizations

1.1.2 Information Systems and Information Technology

1.1.3 Tangible Assets, Intangible Assets, and Human Assets

1.1.4 Vulnerabilities, Threats, and Actors

1.1.5 Security Controls

1.2 The Confidentiality, Integrity, Availability (CIA) Triad

1.3 Data Classification

1.3.1 Sensitive Information

1.3.2 Confidential Information

1.3.3 Personally Identifiable Information (PII)

1.3.4 Protected Health Information (PHI)

1.4 Closing Thoughts

1.5 Summary

1.6 Review Questions

1.7 Answers to Review Questions