Cyber and information security
Also known as: information security, cybersecurity, infosec
Protecting an organisation's data, systems and ways of working against loss, misuse and interruption.
Draft - this entry has not been reviewed yet.
Formal
The discipline of keeping information, and the systems that handle it, confidential, correct and available - whether the information is digital or on paper. It covers technology, processes, people and physical surroundings.
In plain English
Like looking after a house - you lock the doors, check nothing has been tampered with, and make sure the family can still get in when they need to.
In practice
A small Danish accounting firm turns on encryption on its laptops, keeps offline copies of client files and teaches staff to spot fake emails that pretend to come from the tax authorities - all parts of one security effort.
Why it matters
Nearly every business now depends on its data and systems; losing them, even for a day, can halt work, break the law and cost customers' trust.
Technical deep dive
The terms overlap but are defined differently. ISO/IEC 27000 defines information security as the preservation of confidentiality, integrity and availability of information in any form, including paper and speech. The EU Cybersecurity Act, Regulation (EU) 2019/881 Art. 2(1), defines cybersecurity as the activities necessary to protect network and information systems, their users and other persons affected by cyber threats, and NIS2 Art. 6(3) adopts that definition, while Art. 6(2) defines the security of network and information systems as resistance to events that compromise availability, authenticity, integrity or confidentiality. ISO/IEC 27032:2023 treats Internet security as a further subset. The Danish pairing "cyber- og informationssikkerhed", used in the national strategies, deliberately covers both, whereas "IT-sikkerhed" traditionally means the technical subset.
Structurally the discipline is run as a management system. ISO/IEC 27001:2022 specifies an ISMS on the Plan-Do-Check-Act pattern: context and scope (clause 4), leadership (5), risk assessment and treatment (6.1.2 and 6.1.3), operation (8), performance evaluation through internal audit and management review (9.2, 9.3) and continual improvement (10). The NIST Cybersecurity Framework 2.0 organises outcomes in six functions, Govern, Identify, Protect, Detect, Respond and Recover, and is often used alongside ISO as a maturity and communication tool. NIS2 Art. 21(2) sets a minimum list of measures that cover much of the same ground, from risk analysis and incident handling to supply chain security, cryptography and MFA.
The work spans four domains that must be coordinated: technical controls (identity, endpoint, network, cloud, application security, cryptography), processes (change, vulnerability and incident management, continuity), people (awareness, vetting, roles, culture) and physical security. Typical roles include a CISO or information security coordinator, system and information owners, IT operations, a SOC, a data protection officer under GDPR Art. 37 to 39 where required, and internal audit. Separating those who operate controls from those who oversee them is itself a control.
Common misconceptions are that security is an IT project with an end date, that a certificate or a compliance report equals protection, and that it is purely about preventing external attackers, whereas faults, human error, suppliers and insiders cause a large share of incidents. The discipline is also distinct from privacy and data protection, which concern the lawful processing of personal data, even though GDPR Art. 32 requires security of processing, and from safety, which concerns harm to people and the environment, although the two converge in operational technology. Security is steered by risk management, which sets priorities, and by governance, which sets direction and accountability.
Relationships
- Consists of
- CIA triad
- Don't confuse with
- Compliance
- Used with
- GovernanceRisk management
Sources & further reading
Standards & official texts
- ISO/IEC 27000:2018 - Information security management systems - Overview and vocabulary · ISO/IEC
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Mentioned in
Check yourself
Loading…