The CIA triad
Information security protects information and systems from unauthorized access, use, disclosure, disruption, modification, or destruction. The central objectives of information security are commonly described as confidentiality, integrity, and availability.
Confidentiality limits access to authorized people. Integrity protects information from unauthorized changes. Availability ensures authorized users can access information and systems when they need them.
An audit records 34 systems using multi-factor authentication, 21 with an incident-response plan, and 12 with completed access reviews. Security controls are evaluated by how they support one or more of these objectives.
Page 8 of 42