6.1 - Principles of Information Security Flashcards
What is confidentiality? + Example
Information can only be accessed by individuals, groups that have the authorisations to do so.
Give an example of confidentiality
Example:
An organisation/staff should use protection measures such as usernames and passwords to ensure that only authorised people can access the sensitive data.
Access levels or permissions can also limit who has access to the data.
What is integrity
Information should be maintained (checking it) so that it is up to date, accurate, complete and fit for purpose.
Example of integrity
Staff/organisation should carry out regular maintenance to update information.
e.g confirm contact details once a year)
What is availability
information is available to the individuals or groups that need to use it. It should only be available to those who are authorised.
What an example of availability
information is available and usable by individuals, groups, or processes that need to use it.
Example of availability
staff should have the correct privileges so that they can easily access data when required so that it is available remotely using an internet connection
Data must also be kept safe from unauthorised access. staff should not make additional copies of information which could be lost or stolen