Ebook Information security: Fundamentals

The purpose of information security is to protect an organization’s valuableresources, such as information, computer hardware, and software. Throughthe selection and application of appropriate safeguards, security helps theorganization’s mission by protecting its physical and financial resources,reputation, legal position, employees, and other tangible and intangibleassets. To many, security is sometimes viewed as thwarting the businessobjectives of the organization by imposing poorly selected, bothersomerules and procedures on users, managers, and systems. Well-chosen secu-rity rules and procedures do not exist for their own sake — they are putin place to protect important assets and thereby support the overallbusiness objectives.