Information Security

Information security (InfoSec) is the practice of protecting information, whether digital, printed or spoken, from unauthorized access, use, disclosure, alteration or destruction. It is built on the CIA triad: confidentiality (only authorized people can see data), integrity (data stays accurate and unaltered) and availability (data and systems are accessible when needed).

For organizations, information security is as much about people and process as technology. It covers security policies, risk assessment, access control, data protection, staff awareness training, incident response planning and compliance with standards such as ISO/IEC 27001.

In this section

Frequently asked questions

What is the difference between information security and cybersecurity?

Information security protects all information in any form, including paper records and verbal information. Cybersecurity is a subset focused on protecting digital systems, networks and data from cyberattacks. For hands-on technical tutorials, see our Cybersecurity section.

What is the CIA triad?

The CIA triad is the foundational model of information security: confidentiality, integrity and availability. Every security control, from encryption to backups, supports one or more of these three goals.

Why do small businesses need information security?

Small businesses are frequent targets because they often have weaker defenses. Basic measures such as strong access control, regular backups, patching and staff phishing awareness prevent most common attacks.

Written by Mehmood Ali, a certified CEH and CEI instructor and corporate cybersecurity trainer. Need security awareness training for your team? Explore courses at the National Techno Training Institute (NTTI).

Back to top button