Data security is the process of protecting information systems and its data from unauthorized accidental or intentional modification, destruction or disclosure. The protection includes the confidentiality, integrity and availability of these systems and data.
Risk assessment, mitigation and measurement are key components of data security. To maintain a secure environment, data security protocols require that any changes to data systems have an audit trail, which identifies the individual, department, time and date of any system change. Companies utilize personnel, policies, protocols, standards, procedures, software, hardware and physical security measures to attain data security. Data security may include one or a combination of all of these.
Data security is not confined to the Information Services or Information Technology departments, but will involve various stakeholders including senior management, the board of directors, regulators, internal and external auditors, partners, suppliers and shareholders.
Data security encompasses the security of the Information System in its entirety. The U.S. National Information Systems Security Glossary defines Information Systems Security (INFOSEC) as: “The protection of information systems against unauthorized access to or modification of information, whether in storage, processing or transit, and against the denial of service to authorized users or the provision of service to unauthorized users, including those measures necessary to detect, document, and counter such threats.“
Protecting data from unauthorized access is one component of data security that receives a great deal of attention. The concern for data protection extends beyond corporate concerns but is a high priority consumer interest as well. Data can be protected against unauthorized access through a variety of mechanisms. Passwords, digital certificates and biometric techniques all provide a more secure method to access data. Once the authorized user has been authorized or authenticated, sensitive information can be encrypted to prevent spying or theft. However, even the most sophisticated data security programs and measures cannot prevent human error. Security safeguards must be adhered to and protected to be effective.
Application Security
|