As defined
by ISO 17799, information as an asset that may exist in many forms and has value
to an
organization. Information security is characterized as the preservation of:
· Confidentiality – ensuring that information is accessible only
to those authorized to have
access.
· Integrity – safeguarding the accuracy and completeness of information
and processing
methods.
· Availability – ensuring that authorized users have access to
information and associated
assets when required.
Valuable reading for understanding ISO 17799, the
regulatory basis and genesis of Sarbanes-Oxley