Big4Guy

Welcome to Big4Guy.com. Big4Guy is an online resource where I will share with you the latest news, insights, knowledge and some experiences as a Big 4 consultant. We will discuss some of the important issues which organisations are facing today in the areas of information security, security and controls in SAP R/3, Oracle Applications, J.D.Edwards, Peoplesoft and various other ERP's. You will also find information on latest complaince regulations like Sarbanes Oxley, Basel II and so on. Big4guy will also attempt to provide valuable resources for individuals interested in examinations the CISA, CISM, CISSP, PMP and various other security certifications considered essential for entry in any Big 4 accounting, auditing and consulting firms. You are invited to post your comments and viewpoints to posts here. I sincerely hope this online journal will be useful to everyone from a budding student to a professional in the accounting, auditing, management and consultancy professions.

Post details: The BIG Three CIA Confidentiality, Integrity and Availability Principles of Information Security

01/12/06

Permalink 09:46:26 pm, Categories: Me, Myself & I, Information Security, 239 words   English (US)

The BIG Three CIA Confidentiality, Integrity and Availability Principles of Information Security

When do you call a piece of information as secure? One BIG question, three timeless prinicples. Information or for that matter data is said to be secure if it satisfies three information security pricniples. These principles popularly known as CIA, confidentiallity, Integrity and Availability apply irrespective of the technology platform, the size of organziation etc. I am discussing what these principles actually mean and how they apply to your organization.

Confidentiality - Confidentiality means preventing sensitive information from being disclosed to unauthorized recipients. Unauthorized disclosure of information may happen through intentional release, misapplication of rights etc. Such unauthorized disclosure of information may cause financial loss, public embaressment, or put the organization under legal liability.

Integrity - Integrity refers to changing information resources only in a specifed and authorized manner. Let me put it in other words, integrity simply is to ensure that data remains consistent and changes to data are authorized by appropriate personnel. In case of lack of integrity, there is always a risk that information may be accidentally or intentionally manipulated.

Availability - Availability ensures that systems operate as required and authorized users are not denied service. To put it in a layman's language, availability means systems are available when needed and computing resources can be accessed by auhtoirzed users at all times. Lack of availability of information systems may result in missed oppurtunities or interruption of operations.

More on Information Security >>

Protocols , Buffer Overflow Attack , Denial of Service Attack

Comments:

No Comments for this post yet...

Official Websites

Search

Google

Web Big4Guy.com

September 2008
Mon Tue Wed Thu Fri Sat Sun
<<  <   >  >>
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30          

Misc

Syndicate this blog XML

What is RSS?