# What is Information Security?

> Information security is the coordinated protection of information and the systems, people, facilities, and processes that handle it.

- Canonical URL: https://yellowcube.eu/glossary/information-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Its core objectives are to preserve confidentiality, integrity, and availability against unauthorized access, use, disclosure, alteration, or destruction, as well as accidental failures, environmental hazards, and other causes of disruption or loss. It applies to information in digital, physical, printed, spoken, and other forms throughout its lifecycle.

Effective information security connects governance and risk decisions to administrative, physical, personnel, and technical safeguards. The required protection depends on the information’s value, use, obligations, threats, dependencies, and the consequences of compromise.

### Key points

- **Priority setting:** Identify important information and services, assign accountable owners, understand authorized uses and flows, and assess plausible threats, vulnerabilities, impacts, and dependencies.
- **Proportionate safeguards:** Combine policy, training, access control, secure architecture, physical protection, monitoring, resilience, supplier controls, and incident preparation according to risk.
- **Operation and improvement:** Maintain assets and controls, manage changes and exceptions, investigate events, test recovery, measure outcomes, and revise protection when business or threat conditions change.
- **Important limitation:** Confidentiality, integrity, and availability are essential objectives, not proof of security. Controls involve trade-offs and residual risk; excessive restriction can also damage availability, safety, usability, or the organization’s mission.

### Related terms

[Cybersecurity](<https://yellowcube.eu/glossary/cybersecurity/>) · [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/>) · [Defense in depth](<https://yellowcube.eu/glossary/defense-in-depth/>) · [Data security](<https://yellowcube.eu/glossary/data-security/>) · [Information security policy](<https://yellowcube.eu/glossary/information-security-policy/>) · [Confidentiality, integrity, and availability (CIA triad)](<https://yellowcube.eu/glossary/confidentiality-integrity-and-availability/>) · [Operational security (OPSEC)](<https://yellowcube.eu/glossary/operational-security/>)

### Sources

[NIST FIPS 199, Standards for Security Categorization of Federal Information and Information Systems](https://csrc.nist.gov/pubs/fips/199/final) · [NIST SP 800-12 Rev. 1, An Introduction to Information Security](https://csrc.nist.gov/pubs/sp/800/12/r1/final) · [ISO/IEC 27001:2022, Information security management systems — Requirements](https://www.iso.org/standard/27001)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

