Page 10 - CISSO_Prep_ Guide
P. 10

real role of the security team is to serve the organization - to be
            an integral part of the business processes.

            Information security is the protection of information - ensuring
            the defense, stability, and availability of the data and systems
            needed to support business objectives. As will be seen in the
            book, information security is a complicated and broad field and
            encompasses nearly every aspect of business today. The
            information must be protected throughout the information
            lifecycle - at all times, from the initial gathering of the
            information, through its processing, storage, transmission, and
            reporting, until the day it is discarded. Information on systems,
            networks, and paper. A breach is not just the theft of information
            by an outsider. It may also provide access by an unauthorized
            insider, the contamination or release of data intentionally or
            accidentally — the failure of equipment that was meant to
            protect the data and the circumvention of the business
            procedure. Just as information touches every area of business
            today, so also does the task of information security - reaching
            into the realms of physical security, law, business continuity,
            and compliance.

            The information must be protected at all times, in all places and
            all forms. This is what makes the field of information security
            management exciting, ever-changing, and rewarding.
   5   6   7   8   9   10   11   12   13   14   15