Basic Information Security Concepts

Several different concepts are helpful in understanding information security and the laws that affect it. Laws that regulate information security often use risk management, the process of understanding the risks that an organization faces and then taking steps to address or mitigate them, to justify them. You will briefly learn about basic risk management concepts and terms here.


A vulnerability is a weakness or flaw in an information system. They may be construction or design mistakes, as well as flaws in how an internal safeguard is used or not used. Not using antivirus software on a computer, for instance, is a vulnerability. Vulnerabilities can be exploited (used in an unjust way) to harm ...

Get Legal and Privacy Issues in Information Security, 3rd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.