What is Information Security?

Information security is intended to ensure the confidentiality, integrity and availability of information. The information can be available on IT systems or in non-digital form.

Information security protection goals

The most important things in a nutshell

  • Information security aims to protect information from theft, unauthorized modification or destruction.
  • Information can be digital or non-digital.
  • IT security is a subfield of information security that deals with the protection of digitally present information.
  • The most important protection goals of information security are
  • The prevention of unauthorized access (),
  • the protection against unauthorized modification () and
  • the protection against destruction ().
  • Depending on the application, other protection goals may be relevant and considered.
Serie Informationssicherheit

Importance of information security

The information security aims to protect information from theft, unauthorized modification or destruction. Information can exist either digitally in IT systems or, for example, in paper form.

What information is worth protecting?

Information worth protecting is often success-relevant and confidential company data such as customer inventories, company strategies, in-house developments or know-how. Due to strict legal requirements, the protection of personal data is particularly important. This includes, for example, the purchasing behavior of the company’s own customers or the personal data of its employees.

Protection goals information security

The main protection goals of IT and information security. (ISO/IEC 27001, IT-Grundschutz , DSGVO) are included:

  • Protection of confidentiality (engl. confidentiality; no access to sensitive data for unauthorized third parties),
  • Protection of integrity (engl. integrity; no falsification).
  • Protection of availability (Engl. availabilty; data are available when they are needed).

Depending on the use case, other protection goals of information security can be included in the consideration.

cia confidentiality

Protection goal confidentiality of information

In information security, confidentiality means that data is accessible only to authorized individuals.

Examples
  • Company data worthy of protection should always be stored on cloud services or your own computers in such a way that only authorized employees have access to it. (Access protection with user rights)
  • When accessing a server, data transmission should be encrypted so that no one can read the transmitted passwords and information (transport encryption).
Confidentiality attacks:
  • Every data leak is an attack on the confidentiality of information. Unfortunately, these happen far too often – with the larger ones also being often a news story. Services like Have I Been Pwned? track these Data leaks (also called data breaches).
cia integrity

Protection goal integrity of information

Integrity of data and information means that no unauthorized modification has been made.

Example
  • When transferring money online, both the amount of money and the recipient account should not be able to be changed during the transfer to the bank server.
Integrity attacks:
  • An integrity attack is the unauthorized addition of an administrator role to a user. Integrity attacks can be very consequential. In a ransomware incident, if an organization’s Active Directory has been unauthorizedly has been modified, a complete rebuild of the AD is often a mandatory consequence.
  • But also any other type of change such as a changed sender of an email of an e-mail falls under it.
cia availability

Protection goal availability of information

Availability of information means that all retrieved information can be used in a timely manner and can be used in accordance with expectations.

Example
  • After logging in to your cloud service, for example Microsoft Office 365, all documents will be available after a few seconds.
  • On the user computer, all stored files can be accessed.
Attacks on availability:
  • At their core, current ransomware attacks on enterprises are often classic Availability Attacks. All data and accessible backups are encrypted or deleted in exchange for a cryptocurrency ransom (with a lot of luck…) to be available again. It should be noted that with ransomware at the moment, attacks on the confidentiality and integrity of information also frequently take place.
  • However, other attacks such as DDoS attacks are also common.

Do you need reliable experts to help you protect your IT systems ?

Let’s talk about it today!

Other information security protection goals

In Art. 32 para. 1b DSGVO, the so-called resilience is additionally required as a further protection goal. This is regularly understood to mean the availability of IT systems even under load conditions.

Depending on the use case, in addition to the protection goals of confidentiality, integrity and availability, other protection goals are considered.

dsgvo1

Authenticity protection goal

Authenticity refers to both ensuring the identity of the communication partner and ensuring the originator of data. Authenticity is often considered the overriding protection goal. Other protection goals are worthless if it is not possible to determine whether communication is taking place with the desired communication partner.

Example

The purpose of a username/password login is to ensure that the correct communication partner is on the other end of the line. This simple example also illustrates that in order to achieve the three primary protection goals of information security.

Protection goal of non-repudiation

Non-repudiation is intended to ensure that a communication cannot be subsequently denied to third parties by a party involved. (English: non-repudiation).

Example
  • For digital signatures, non-repudiation, along with authenticity, is critical.
  • If contracts (online) are concluded, non-repudiation is important for the service provider.

Protection goal bindingness

When authenticity and non-repudiation of a communication are ensured, it is also called binding.

Threats to information security protection goals

There are hundreds of categories of threats that threaten information security protection goals in one way or another. Below, we cover some of the most important modern threats to protection goals that are current priorities for enterprise security teams.

guide informationsecurity 2

Inadequately secured or unpatched systems

The speed and evolution of technology often leads to compromises in security measures. In other cases, systems are developed without regard to security and remain in operation as legacy systems within an organization. Organizations need to identify these poorly secured systems and mitigate the threat by securing, patching, decommissioning or isolating them.

Attacks involving use of social media

Many people have accounts on social media where they often inadvertently disclose information. Attackers can exploit this type of information to launch attacks.

Social Engineering

In social engineering, attackers manipulate IT system users through psychological triggers such as curiosity or fear to achieve a desired response.

Because the source of a social engineering message usually appears trustworthy, users often click on a link that installs malware on the computer they are using. This exposes personal information, login credentials and other corporate data that the user has access to to the attacker.

Companies can mitigate social engineering by training users to recognize suspicious social engineering messages and forward them to the security team. But technical systems such as email filtering systems can also play a role.

Malware on clients

Enterprise users work with a variety of endpoints, including mobile devices such as laptops, tablets and smartphones. A key threat to all of these endpoints is malware, which can be transmitted in a variety of ways. It can lead to the compromise of the client itself as well as the extension of privileges to other clients and servers.

Missing mobile device encryption

Encryption methods encrypt data so that it can only be decrypted by users with secret keys. Using cryptography for encryption is very effective in preventing data loss or corruption when devices are lost or stolen.

Inaccurate or inadequate security configuration of cloud services

Modern enterprises often use a variety of platforms and cloud services. Almost all of these services have sophisticated built-out security features, but they must be configured and customized by the enterprise to meet its needs. Incorrect or negligent security configuration, or even human error, can easily lead to a serious security incident.

Information security protection goals – what measures can be used to achieve them?

Achieving the protection goals relevant to information security involves both organizational and technical measures.

An Information Security Management System (ISMS) is regularly used for the holistic management of information security in the company. In this context, responsibility for information security and the ongoing operation of the ISMS is delegated to an information security officer (ISO).

Frequently asked questions

Information security covers all measures that protect information – whether digital or non-digital – from theft, unauthorized modification and destruction. Its core protection goals are confidentiality, integrity and availability. IT security is the subfield that deals specifically with digitally stored information.

The three primary protection goals are confidentiality (no access by unauthorized parties), integrity (no unauthorized modification) and availability (information is available when needed). Together they form the CIA triad and are the foundation of every security concept.

Information security protects all information – digital as well as on paper. IT security is a subfield of it and deals exclusively with protecting digitally stored information in IT systems. Information security is therefore the broader term.

Depending on the use case, further protection goals apply: authenticity (verified identity of the communication partner and data origin), non-repudiation (a communication cannot later be denied) and bindingness (authenticity and non-repudiation combined). These are especially critical for digital signatures.

Key modern threats include unpatched or poorly secured systems, social engineering, malware on endpoints, missing encryption on mobile devices, misconfigured cloud services and information disclosed via social media. Ransomware attacks often endanger confidentiality, integrity and availability at the same time.

The protection goals are achieved through organizational and technical measures. An Information Security Management System (ISMS) is typically used for holistic governance, operated under the responsibility of an Information Security Officer. Typical technical measures include encryption, access control and transport encryption.

Have we sparked your interest?

Just give us a call or write us a message!

You can reach us by phone or via our contact form. We look forward to hearing from you!

Your request

Data protection

Related content

CIS Controls - A Quick Overview of CIS Controls

CIS Controls – A Quick Overview of CIS Controls

The CIS Critical Security Controls (CIS Controls) are a prioritized list of protective measures to defend against the most common cyber attacks on IT systems.

Information Security Management Systems (ISMS)

Information Security Management Systems (ISMS)

An Information Security Management System (ISMS) defines methods to ensure information security in an organisation.

CVSS (Common Vulnerability Scoring System)

CVSS (Common Vulnerability Scoring System)

The CVSS Score provides a numerical representation (0.0 to 10.0) of the severity of a security vulnerability in IT. We explain how the Common Vulnerability Scoring System works, how CVSS should be…

NTLM Authentication

NTLM Authentication

In this article, we explain what NTLM authentication is, how it works, and how it can be exploited by attackers.

Top 10 Vulnerability Scanners for 2026

Top 10 Vulnerability Scanners for 2026

Vulnerability scanners are automated tools that organisations can use to monitor their networks, systems and applications for security weaknesses. Vulnerability scanning is a best practice in…

Need to Know Principle

Need to Know Principle

The need-to-know principle describes a security objective for confidential information. Access should only be granted to a user if the information is immediately needed to perform a task.

Endpoint Security

Endpoint Security

Endpoint security comprises technologies and measures that protect end devices such as laptops, servers, smartphones and IoT devices against cyber threats.

What is MITRE ATT&CK?

What is MITRE ATT&CK?

The MITRE ATT&CK Framework is a continuously updated knowledge base consisting of cyber attacker tactics and techniques across the attack lifecycle.

Proxy Server

Proxy Server

A proxy server works as an intermediary between two IT systems. Proxy servers offer different functionalities, improved security and optimised data protection depending on the application, need or…

Cybersecurity concept in 8 steps

Cybersecurity concept in 8 steps

A cybersecurity security concept refers to guidelines that are intended to ensure IT security in the company. It is about ensuring the availability, integrity and confidentiality of company data,…

Buffer Overflow

Buffer Overflow

A buffer overflow is a programming error that can be exploited by hackers to gain unauthorized access to IT systems. It is one of the best-known security vulnerabilities in software, yet it is…

Attack Vector and Attack Surface

Attack Vector and Attack Surface

An attack vector is a way for attackers to penetrate a network or IT system. Typical attack vectors include…

Authentication: Differences to authorisation

Authentication: Differences to authorisation

Authentication and authorization are two words used in IT-Security. They might sound similar but are completely different from each other. Authentication is used to authenticate someone’s identity…

What is data security? Standards & Technologies

What is data security? Standards & Technologies

Data security is an important topic for all companies and authorities. Learn more about threats, measures and the legal framework here.