Information security means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.



Basic principles:




Confidentiality is the term used to prevent the disclosure of information to unauthorized individuals or systems.


In information security, integrity means that data cannot be modified undetectably. Integrity is violated when a message is actively modified in transit.


The information must be available when it is needed. The aim is to have it available at all times, preventing service disruptions due to power outages, hardware failures, and system upgrades..


It is necessary to ensure that the data, transactions, communications or documents are genuine. It is also important for authenticity to validate that both parties involved are who they claim they are
Risk management  
A risk assessment is carried out by a team of people who have knowledge of specific areas of the business.

Risk: is the likelihood that something bad will happen that causes harm to an informational asset (or the loss of the asset).

Vulnerability: is a weakness that could be used to endanger or cause harm to an informational asset.

Threat: is anything (man made or act of nature) that has the potential to cause harm. The CISA Review Manual 2006 provides the following definition of risk management: "Risk management is the process of identifying vulnerabilities and threats to the information resources used by an organization in achieving business objectives, and deciding what countermeasures, if any, to take in reducing risk to an acceptable level, based on the value of the information resource to the organization."[

