1 Security Concepts of Information Assurance
The chapter introduces the basic language of cybersecurity by showing that organizations rely on people, processes, and technology to create value, and that all of these depend on assets that must be protected. It explains that assets can be tangible, intangible, or human, ranging from buildings and hardware to data, reputation, and employees. Because these assets support business operations, cybersecurity is framed as a discipline focused on preserving continuity and reducing disruption across interconnected systems.
It then builds the core security model around vulnerabilities, threats, attacks, and threat actors. A vulnerability is any weakness that can be exploited, while threats are the conditions or events that can cause harm, whether accidental or deliberate. The chapter distinguishes non-malicious and malicious threats, describes common threat actors such as insiders, hackers, cybercriminals, hacktivists, competitors, and nation-state groups, and emphasizes that security controls must be chosen based on the asset being protected and the risks it faces.
Finally, the chapter presents information assurance through the CIA triad: confidentiality, integrity, and availability. Confidentiality limits access to authorized users, integrity keeps information accurate and unaltered, and availability ensures systems and data are accessible when needed; these principles are threatened by disclosure, alteration, and denial. The chapter closes by explaining that data classification helps organizations prioritize protection according to sensitivity and business impact, with categories such as public, internal, confidential, and restricted, and with special attention to sensitive data like PII and PHI.
Illustration of the interdependence of the key information security principles of confidentiality, integrity, and availability along with the corresponding threats of disclosure, alteration, and denial.
Answers to Review Questions
- The correct answer is D. Software is not a tangible asset. Unlike hardware, buildings, and machines, which have a physical form and can be touched, software is intangible. It consists of code and data that exist digitally rather than physically.
- The correct answer is C. Availability is the component of the CIA triad that focuses on ensuring that information is available when it is needed. On the other hand, while Confidentiality and Integrity are part of the CIA, they have different purposes. Authentication is not part of the CIA triad.
- The correct answer is A. Any factor that has the potential to disrupt an asset by exploiting a vulnerability is known as a threat. Threats can take many forms, including malicious actors such as hackers, computer viruses, or natural disasters such as hurricanes or earthquakes. The remaining options, on the other hand, are not threats because the first two unchecked options represent vulnerabilities, and the last unchecked option emphasizes the need for protective measures on an asset to counter potential threats.
- The correct answer is C. A threat actor is an individual or entity responsible for launching cyberattacks. The remaining options are incorrect because a software vulnerability is a vulnerability, a phishing email is a threat vector, and a denial-of-service attack is an example of an attack method.
- The correct answer is B. Personally Identifiable Information (PII) is any information that can be used to identify, distinguish, or trace an individual's identity. A Social Security number is a direct identifier and therefore constitutes PII. The other options contain organizational or aggregated information that does not identify a specific individual.
Fundamentals of Cybersecurity ebook for free