EMZETT.
Login

IT security

In short: IT security protects information and IT systems against loss, misuse and attacks.

In more detail: It covers technology, processes and the behaviour of people. The basis is the protection goals.

In Depth

Protection goals

  • Confidentiality: only authorised people see the data (encryption, access rights).
  • Integrity: data stays unchanged and correct (hashing, signatures).
  • Availability: systems and data are usable when needed (redundancy, backups).
  • Often also: authenticity (is it genuine?) and non-repudiation.

Measures

  • Technical: firewall, antivirus, updates, two-factor login, encryption, backups.
  • Organisational: rules, permission concept, emergency plan, staff training.
  • Physical: access control, fire protection, server room (data centre).

Threats

malware, phishing, DDoS, ransomware, operator error, hardware failure. People are often the weakest link (social engineering).

Standards

BSI IT-Grundschutz and ISO/IEC 27001 describe how security is organised. See also security and cybersecurity.

See also: security by design, security by default, IT security in web development