Skip to content

Information Assurance

What is Information Assurance?

Practices for managing risks related to the use, processing, storage, and transmission of information to ensure its confidentiality, integrity, and availability.

Information Security

What the standards actually require on information assurance

Requirements naming information assurance across 4 standards, quoted from the control text.

Document trade-offs among security objectives, system performance, cost, and schedule, ensuring decisions are informed and approved by an appropriate authority.

SE-IA · Information Assurance and Security Engineering Trade-offs
MITRE D3FEND1 control

Establish the scope of MITRE D3FEND (Detection, Denial and Disruption Framework Empowering Network Defense) - defensive cybersecurity countermeasure knowledge graph developed by MITRE Corporation under funding from National Security Agency (NSA) Information As...

MITRE-D3FEND-Scope-MITRE-NSA-2021-CC-BY-4-0-Countermeasure-Knowledge-Graph-Companion-ATTACK-Ontology · MITRE D3FEND Scope + MITRE + NSA 2021 + CC BY 4.0 + Countermeasure Knowledge Graph + Companion to ATT&CK + Ontology

Establish incident response procedures for label failures including incorrect labelling + over-classification + under-classification + label loss in transit + label corruption.

STANAG-7 · Incident Response, User Training, and Label Audit

Per UK Defence Standard 05-138 + Cyber Defence Information Assurance Notice (DCDP): Cyber Risk Profile + Risk Assessment + applicability per CRP level.

UKDEFSTD-1 · Cyber Defence Cyber Risk Profile (CRP)

Questions people ask about information assurance

What is Information Assurance?
Practices for managing risks related to the use, processing, storage, and transmission of information to ensure its confidentiality, integrity, and availability.
Why is Information Assurance important for compliance?
Information Assurance is a key concept in Information Security. Understanding information assurance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Information Assurance?
Information Assurance appears in the requirement text of NIST SP 800-160, MITRE D3FEND, NATO STANAG 4774 (Confidentiality Metadata Labels) and STANAG 4778 (Metadata Binding), UK Defence Standard 05-138 - Cyber Security for Defence Suppliers. Across these standards we have identified 4 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Information Assurance?
Explore our compliance framework pages to see how information assurance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Information Assurance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.