Overview

1 Security Concepts of Information Assurance

Organizations depend on a mix of people, processes, and infrastructure to create value, and cybersecurity exists to protect those elements from disruption. The chapter introduces the basic building blocks of the field by explaining what assets are, why they matter, and how they can be categorized as tangible, intangible, or human. It also distinguishes information systems from information technology and shows that cybersecurity is part of the broader discipline of information security, which protects information in both physical and digital forms.

A major focus of the chapter is the relationship between vulnerabilities, threats, attacks, and threat actors. Vulnerabilities are weaknesses that can be exploited, while threats are the factors that act on those weaknesses to cause harm. The text describes a range of threat actors, from insiders and script kiddies to cybercriminal organizations and nation-state groups, and emphasizes that controls must be chosen based on the asset being protected and the risks it faces. Security controls are grouped into physical, technical, and administrative measures, and together they support resilience and continuity.

The chapter also presents the CIA triad as the core model for understanding information assurance: confidentiality, integrity, and availability. Each principle can be threatened by disclosure, alteration, or denial, and different safeguards help preserve each one, such as encryption for confidentiality, hashing and digital signatures for integrity, and redundancy or backups for availability. Finally, the chapter explains that data classification helps organizations assign appropriate protection based on value and sensitivity, with categories such as public, internal, confidential, and restricted guiding how information should be handled, stored, and secured.

Illustration of the interdependence of the key information security principles of confidentiality, integrity, and availability along with the corresponding threats of disclosure, alteration, and denial.

Answers to Review Questions

  1. The correct answer is D. Software is not a tangible asset. Unlike hardware, buildings, and machines, which have a physical form and can be touched, software is intangible. It consists of code and data that exist digitally rather than physically.
  2. The correct answer is C. Availability is the component of the CIA triad that focuses on ensuring that information is available when it is needed. On the other hand, while Confidentiality and Integrity are part of the CIA, they have different purposes. Authentication is not part of the CIA triad.
  3. The correct answer is A. Any factor that has the potential to disrupt an asset by exploiting a vulnerability is known as a threat. Threats can take many forms, including malicious actors such as hackers, computer viruses, or natural disasters such as hurricanes or earthquakes. The remaining options, on the other hand, are not threats because the first two unchecked options represent vulnerabilities, and the last unchecked option emphasizes the need for protective measures on an asset to counter potential threats.
  4. The correct answer is C. A threat actor is an individual or entity responsible for launching cyberattacks. The remaining options are incorrect because a software vulnerability is a vulnerability, a phishing email is a threat vector, and a denial-of-service attack is an example of an attack method.
  5. The correct answer is B. Personally Identifiable Information (PII) is any information that can be used to identify, distinguish, or trace an individual's identity. A Social Security number is a direct identifier and therefore constitutes PII. The other options contain organizational or aggregated information that does not identify a specific individual.

FAQ

What is the main goal of cybersecurity in an organization?

The main goal is to protect the organization’s infrastructure, processes, people, and assets from threats and adverse events while maintaining business continuity.

What is an asset in cybersecurity?

An asset is any item that has value to the organization and requires protection. Assets can be tangible, intangible, or human-related.

What are the three parts of an organization’s infrastructure?

An organization’s infrastructure includes physical elements, digital elements, and the technologies that support operations. Physical infrastructure includes buildings and hardware, while digital infrastructure includes software, networks, and data.

What is the CIA triad?

The CIA triad is the core security model in cybersecurity. It stands for Confidentiality, Integrity, and Availability, which are the three key properties that security controls aim to protect.

What does confidentiality mean in the CIA triad?

Confidentiality means information is accessible only to authorized parties. It is commonly protected against disclosure through controls such as encryption, authentication, authorization, and least privilege.

What is the difference between a vulnerability and a threat?

A vulnerability is a weakness that can be exploited, while a threat is any factor that can act on that weakness to cause harm or disruption to an asset.

What is a threat actor?

A threat actor is the person or group responsible for carrying out an attack. Examples include insiders, script kiddies, hacktivists, cybercriminal organizations, competitors, and nation-state actors.

What are the main categories of security controls?

Security controls are commonly grouped into physical, technical, and administrative controls. Physical controls protect facilities and tangible assets, technical controls protect digital systems and data, and administrative controls include policies, procedures, and training.

What is data classification?

Data classification is the process of evaluating how important or sensitive data is and assigning it a classification level so the appropriate protection measures can be applied.

What is the difference between sensitive information, confidential information, PII, and PHI?

Sensitive information is any information that could harm an individual or organization if improperly disclosed. Confidential information is sensitive information that must be kept private. PII is information that can identify an individual, and PHI is health-related information linked to a specific individual.

pro $24.99 per month

  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose one free eBook per month to keep
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime

lite $19.99 per month

  • access to all Manning books, including MEAPs!

team

5, 10 or 20 seats+ for your team - learn more


choose your plan

team

monthly
annual
$49.99
$499.99
only $41.67 per month
  • five seats for your team
  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose another free product every time you renew
  • choose twelve free products per year
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime
  • renews annually, pause or cancel renewal anytime
  • Fundamentals of Cybersecurity ebook for free
choose your plan

team

monthly
annual
$49.99
$499.99
only $41.67 per month
  • five seats for your team
  • access to all Manning books, MEAPs, liveVideos, liveProjects, and audiobooks!
  • choose another free product every time you renew
  • choose twelve free products per year
  • exclusive 50% discount on all purchases
  • renews monthly, pause or cancel renewal anytime
  • renews annually, pause or cancel renewal anytime
  • Fundamentals of Cybersecurity ebook for free