Overview

1 Security Concepts of Information Assurance

The chapter introduces the basic language of cybersecurity by showing that organizations rely on people, processes, and technology to create value, and that all of these depend on assets that must be protected. It explains that assets can be tangible, intangible, or human, ranging from buildings and hardware to data, reputation, and employees. Because these assets support business operations, cybersecurity is framed as a discipline focused on preserving continuity and reducing disruption across interconnected systems.

It then builds the core security model around vulnerabilities, threats, attacks, and threat actors. A vulnerability is any weakness that can be exploited, while threats are the conditions or events that can cause harm, whether accidental or deliberate. The chapter distinguishes non-malicious and malicious threats, describes common threat actors such as insiders, hackers, cybercriminals, hacktivists, competitors, and nation-state groups, and emphasizes that security controls must be chosen based on the asset being protected and the risks it faces.

Finally, the chapter presents information assurance through the CIA triad: confidentiality, integrity, and availability. Confidentiality limits access to authorized users, integrity keeps information accurate and unaltered, and availability ensures systems and data are accessible when needed; these principles are threatened by disclosure, alteration, and denial. The chapter closes by explaining that data classification helps organizations prioritize protection according to sensitivity and business impact, with categories such as public, internal, confidential, and restricted, and with special attention to sensitive data like PII and PHI.

Illustration of the interdependence of the key information security principles of confidentiality, integrity, and availability along with the corresponding threats of disclosure, alteration, and denial.

Answers to Review Questions

  1. The correct answer is D. Software is not a tangible asset. Unlike hardware, buildings, and machines, which have a physical form and can be touched, software is intangible. It consists of code and data that exist digitally rather than physically.
  2. The correct answer is C. Availability is the component of the CIA triad that focuses on ensuring that information is available when it is needed. On the other hand, while Confidentiality and Integrity are part of the CIA, they have different purposes. Authentication is not part of the CIA triad.
  3. The correct answer is A. Any factor that has the potential to disrupt an asset by exploiting a vulnerability is known as a threat. Threats can take many forms, including malicious actors such as hackers, computer viruses, or natural disasters such as hurricanes or earthquakes. The remaining options, on the other hand, are not threats because the first two unchecked options represent vulnerabilities, and the last unchecked option emphasizes the need for protective measures on an asset to counter potential threats.
  4. The correct answer is C. A threat actor is an individual or entity responsible for launching cyberattacks. The remaining options are incorrect because a software vulnerability is a vulnerability, a phishing email is a threat vector, and a denial-of-service attack is an example of an attack method.
  5. The correct answer is B. Personally Identifiable Information (PII) is any information that can be used to identify, distinguish, or trace an individual's identity. A Social Security number is a direct identifier and therefore constitutes PII. The other options contain organizational or aggregated information that does not identify a specific individual.

FAQ

What is information assurance in cybersecurity?Information assurance is the activity of protecting information and information systems from threats that could compromise confidentiality, integrity, and availability.
What is the difference between cybersecurity and information security?Information security protects all information in all forms, both physical and digital. Cybersecurity is a specialized part of information security focused on protecting digital systems, networks, and data from threats.
What is an asset in cybersecurity?An asset is any item that has value to the organization and requires protection. Assets can be tangible, intangible, or human.
What are the three parts of the CIA Triad?The CIA Triad stands for Confidentiality, Integrity, and Availability. These are the core security properties that organizations aim to protect.
What does confidentiality mean in the CIA Triad?Confidentiality means information is accessible only to authorized parties. A common threat to confidentiality is disclosure.
What is a vulnerability?A vulnerability is any weakness that can be exploited. Vulnerabilities may come from software bugs, misconfigurations, poor security practices, or human error.
What is the difference between a threat and an attack?A threat is any factor that can exploit a vulnerability and disrupt an asset. An attack is the intentional exploitation of a vulnerability in an asset.
What are the main categories of security controls?Security controls are commonly grouped into physical, technical, and administrative controls. These safeguards help reduce vulnerabilities and limit the impact of threats.
What is data classification and why is it important?Data classification is the process of evaluating how important or sensitive data is and assigning it a classification level. It helps organizations apply the right protection based on the data’s value and sensitivity.
What is Personally Identifiable Information (PII)?PII is sensitive information made up of one or more attributes that can identify an individual. Examples include a full name, Social Security number, driver’s license number, and financial information.

pro $24.99 per month

  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose one free eBook per month to keep
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime

lite $19.99 per month

  • access to all Manning books, including MEAPs!

team

5, 10 or 20 seats+ for your team - learn more


choose your plan

team

monthly
annual
$49.99
$499.99
only $41.67 per month
  • five seats for your team
  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose another free product every time you renew
  • choose twelve free products per year
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime
  • renews annually, pause or cancel renewal anytime
  • Fundamentals of Cybersecurity ebook for free
choose your plan

team

monthly
annual
$49.99
$499.99
only $41.67 per month
  • five seats for your team
  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose another free product every time you renew
  • choose twelve free products per year
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime
  • renews annually, pause or cancel renewal anytime
  • Fundamentals of Cybersecurity ebook for free