
211
9
inforMation seCurity
Introduction
Part 1 discusses the basic definition and importance of information
security. Part 2 discusses strategy, methodology, and security stan-
dards, which provides the strategy and methodology, such as ISO
15408, control objectives for information and (related) technology
(COBIT), operationally critical threat, asset and vulnerability evalu-
ation (OCTAVE). In Part 3, a sample security document is provided.
Part 1: Denition and Importance
1. What is information security?
2
.
F
rom what threats does information need to be secured?
3. What kind of information needs to be secured?
What Is Information Security?
Infor