22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

This NIST document provides, on page 5, a definition of computer security.<br />

Computer Security: The protection afforded to an automated information<br />

system in order to attain the applicable objectives of preserving the integrity,<br />

availability and confidentiality of information system resources (includes<br />

hardware, software, firmware, information/data, and telecommunications).<br />

This is a definition that is bit difficult to grasp, so let’s take a small step back. Let’s<br />

define in simpler terms the concepts of both security and IT security.<br />

Security (General)<br />

Security is something that gives or assures safety, such as:<br />

► Measures adopted by a government to prevent espionage, sabotage, or<br />

attack<br />

► Measures adopted by a business or homeowner to prevent a crime such as<br />

burglary or assault.<br />

Security is thus the freedom from risk or danger<br />

Security (Information Technology)<br />

IT Security is also something that gives or assures safety, such as:<br />

► Measures adopted by an IT department to prevent espionage, sabotage, or<br />

attack of their IT architecture<br />

► Measures adopted by an IT department to prevent the defacement, damage<br />

or destruction of their IT architecture<br />

IT Security is also a set of measures adopted by an IT department to prevent<br />

denial of service attacks or any attack preventing access to their IT architecture.<br />

IT Security is thus the freedom from such security risks or dangers; safety for an<br />

IT department (and the company) in knowing that their systems are secure.<br />

Computer security (revisited)<br />

The term computer security, which can be used interchangeably with IT security,<br />

is the facet of computer science whose primary objective is to assure safety of<br />

information and to offer measures to guard against attack, theft, or disclosure so<br />

that:<br />

► The information is timely, accurate, complete, and consistent; and that when<br />

transmitted over a computer network, it has not been changed during<br />

transmission (integrity).<br />

Chapter 1. Fundamentals of IT security 13

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!