Generally Accepted Principles

This section introduces some generally accepted principles that address information security from a high-level viewpoint that can provide comprehensive guidance to organizations.

5 slides · 2 min read · Domain 2

Slide 1

These principles are fundamental in nature and rarely change over time, regardless of technology or industry focus.

They are not stated here as security requirements but are provided as useful references for developing, implementing, and understanding security policies and baselines for use in any organization. The principles listed below are by no means exhaustive and only meant to be examples.

Information System Security Objectives

Information system security objectives or goals are described in terms of three overall objectives: confidentiality, integrity, and availability. Security policies, baselines, and measures are developed and implemented according to these objectives.

External Systems are Assumed to be Unsecure

In general, an external system or entity that is not under your direct control should be considered unsecure. Additional security measures are required when your information assets or information systems are located in, or interfacing with, external systems. Information systems infrastructure could be partitioned using either physical or logical means to segregate environments with different risk levels.

Auditability and Accountability

Security requires auditability and accountability. Auditability refers to the ability to verify the activities in an information system. Evidence used for verification can take the form of audit trails, system logs, alarms, or other notifications. Accountability refers to the ability to audit the actions of all parties and processes that interact with information systems. Roles and responsibilities should be clearly defined, identified, and authorized at a level commensurate with the sensitivity of information.

Prevent, Detect, Respond, and Recover

Information security is a combination of preventive, detective, response, and recovery measures. Preventive measures are for avoiding or deterring the occurrence of an undesirable event. Detective measures are for identifying the occurrence of an undesirable event. Response measures refer to coordinated response to contain damage when an undesirable event (or incident) occurs. Recovery measures are for restoring the confidentiality, integrity, and availability of information systems to their expected state.

Resilience for Critical Information Systems

All critical information systems need to be resilient to withstand major disruptive events, with measures in place to detect disruption, minimize damage, and rapidly respond and recover.

Protection of Information While Being Processed, in Transit, and in Storage

Security measures should be considered and implemented as appropriate to preserve the confidentiality, integrity, and availability of information while it is being processed, in transit, and in storage.

Test this domain