IT security
In short: IT security protects information and IT systems against loss, misuse and attacks.
In more detail: It covers technology, processes and the behaviour of people. The basis is the protection goals.
In Depth
Protection goals
- Confidentiality: only authorised people see the data (encryption, access rights).
- Integrity: data stays unchanged and correct (hashing, signatures).
- Availability: systems and data are usable when needed (redundancy, backups).
- Often also: authenticity (is it genuine?) and non-repudiation.
Measures
- Technical: firewall, antivirus, updates, two-factor login, encryption, backups.
- Organisational: rules, permission concept, emergency plan, staff training.
- Physical: access control, fire protection, server room (data centre).
Threats
malware, phishing, DDoS, ransomware, operator error, hardware failure. People are often the weakest link (social engineering).
Standards
BSI IT-Grundschutz and ISO/IEC 27001 describe how security is organised. See also security and cybersecurity.
See also: security by design, security by default, IT security in web development