6.1- Security principles Flashcards
Confidentiality
Information should only be accessed by individuals or groups with the authorisation to do so
e.g Organisations should use protection measures like usernames and passwords to ensure that only authorised people can access sensitive data
Integrity
Information that is maintained so that is is up to data, correct and fit for purpose
Organisations should carry out regular data maintenance to update information. If storing data in a spreadsheet or database, record locking should be used so that only person can edit at a time
Availability
Information is available to the individuals or groups that need to use it. It should only be available tot those who are authorised.
Staff should have the correct privileges so that they can easily access data when required. Data should be stored online e.g cloud storage so that is is remotely available