Page 10 - CISSO_Prep_ Guide
P. 10
real role of the security team is to serve the organization - to be
an integral part of the business processes.
Information security is the protection of information - ensuring
the defense, stability, and availability of the data and systems
needed to support business objectives. As will be seen in the
book, information security is a complicated and broad field and
encompasses nearly every aspect of business today. The
information must be protected throughout the information
lifecycle - at all times, from the initial gathering of the
information, through its processing, storage, transmission, and
reporting, until the day it is discarded. Information on systems,
networks, and paper. A breach is not just the theft of information
by an outsider. It may also provide access by an unauthorized
insider, the contamination or release of data intentionally or
accidentally — the failure of equipment that was meant to
protect the data and the circumvention of the business
procedure. Just as information touches every area of business
today, so also does the task of information security - reaching
into the realms of physical security, law, business continuity,
and compliance.
The information must be protected at all times, in all places and
all forms. This is what makes the field of information security
management exciting, ever-changing, and rewarding.