Information Security
What is Information Security?
The practice of protecting information by mitigating risks to its confidentiality, integrity, and availability. Governed by frameworks such as ISO 27001 and NIST CSF.
Related terms
Frameworks that govern information security
What the standards actually require on information security
Requirements naming information security across 6 standards, quoted from the control text.
Requires the organisation to plan how information security will be maintained at an appropriate level while a disruption is under way.
iso-27002-2022::5.29 · Information security during disruption →Define and apply a risk assessment process with criteria, repeatability, and documented results.
27003-6.1.2 · Information Security Risk Assessment →The requirement of ISO/IEC 27001 to implement the risk treatment plan applies to the PIMS, so the privacy controls chosen during treatment must actually be implemented and their implementation evidenced.
iso-27701-2019::5.6.3 · Information security risk treatment →The entity must maintain response plans covering the information security incidents it considers could plausibly occur.
CPS234-P24 · Information Security Response Plans →Requirement defined in ISO 27005:2022, clause 7.2 (Identifying information security risks). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_r...
iso-27005-2022::7.2 · Identifying information security risks →CISO or equivalent role is designated with sufficient authority, independence, and access to the board.
IS-II.C.1 · Information Security Roles and Responsibilities →Questions people ask about information security
What is Information Security?
Why is Information Security important for compliance?
What concepts are related to Information Security?
Which compliance frameworks address Information Security?
Where can I learn more about Information Security?
See how Information Security applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.