Information Security
Unit 1
Information Systems Security
Fundamentals
© ITT Educational Services, Inc. All rights reserved.
Learning Objective
Explain the concepts of information systems security (ISS) as applied to an IT infrastructure. NT2580 Introduction to Information Security
© ITT Educational Services, Inc. All rights reserved.
Page 2
Key Concepts
Confidentiality, integrity, and availability (CIA) concepts Layered security solutions implemented for the seven domains of a typical IT infrastructure
Common threats for each of the seven domains
IT security policy framework
Impact of data classification standard on the seven domains
NT2580 Introduction to Information Security
© ITT Educational Services, Inc. All rights reserved.
Page 3
EXPLORE: CONCEPTS
NT2580 Introduction to Information Security
© ITT Educational Services, Inc. All rights reserved.
Page 4
Introducing ISS
ISS
Information
Systems
Information
NT2580 Introduction to Information Security
© ITT Educational Services, Inc. All rights reserved.
Page 5
In t
fid en tia l ity
The CIA Triad
Co n y rit eg
Availability
NT2580 Introduction to Information Security
© ITT Educational Services, Inc. All rights reserved.
Page 6
Confidentiality
Personal Data and Information
• Credit card account numbers and bank account numbers
• Social Security numbers and address information
Intellectual Property
• Copyrights, patents, and secret formulas
• Source code, customer databases, and technical specifications
National Security
• Military intelligence
• Homeland security and government-related information
NT2580 Introduction to Information Security
© ITT Educational Services, Inc. All rights reserved.
Page 7
Integrity
Maintain valid, uncorrupted, and accurate information. User names and passwords
Patents and copyrights
Source code
Diplomatic information
Financial data
NT2580 Introduction to Information Security
© ITT Educational Services, Inc.