Information Security Management Principles, 4th Edition
by Jeremy Green, Andy Taylor, David Alexander, Amanda Finch, David Sutton
2 INFORMATION RISK
Information assurance (IA) refers to the practice of managing risks related to the use, processing, storage and transmission of information. It involves ensuring that data remains secure, confidential and available to authorised users while maintaining its integrity. IA encompasses a range of activities, including the development of security policies, the implementation of protective measures and the ongoing assessment of systems to identify and mitigate potential threats.
Risk, in the context of IA, is the potential for loss or damage when a threat exploits a vulnerability and causes harm. It involves the probability of a threat occurring and the impact it would have on an organisation’s information assets. Effective ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access