Categories
Information Security: definition, requirements, models and stages
Over the past century, society has experienced the most intense leap in technological evolution in history. And while the word "security" used to refer mainly to physical manifestations of violence and threats, this basic concept has also changed with the development of technology. Information has become a weapon, valuable confidential data that can cause damage no less severe than a sharpest knife. This has given rise to another definition: "Information security". What is it, what functions does it perform, how is it used: we will examine the main questions today in the article from Anexet.
Definition of Information Security (IS)
Information security (Infosec) is a set of measures and technical tools designed to prevent dissemination of confidential information about social entities that could directly or indirectly harm their activities.
Such information may include data on protecting a business from competitive threats or employee misconduct, secret production technologies, state secrets, and even personal information. All of this can be used for selfish purposes. To prevent such cases, activities such as ensuring information security are carried out.
Three main principles of Information Security
Information Security is based on three key principles that enable a comprehensive approach to its implementation. These include system confidentiality, integrity of security measures and availability.
System confidentiality
Information Security is directly related to handling sensitive confidential information and Personal Data. Careful attention must be paid to the entire data set throughout an analysis chain. Analyzed information may only be viewed by authorized individuals after verification, and must remain confidential to all others.
Integrity of Information Security measures
This principle calls for treating Information Security as a single, integrated process, without exceptions or concessions unless they are specified in advance. It is this approach that allows for an impartial assessment of the state of affairs and provides a realistic picture of what is happening.
Availability
This is the ability of approved entities to access any part of information and readiness of security services to process requests.

Why is Information Security necessary?
Of course, the main goal of Information Security is to ensure safety of confidential data about business, individuals, and the state; to neutralise negative impacts and damage to companies or individuals. However, this does not mean that every potential threat to Information Security has an exclusively negative goal – the destruction of the object of interest. This is not always true. Information is often needed for analytical purposes: to compare competitors' products with one's own, to analyse effectiveness of business strategies, and to modify production and internal company processes. Various sources can be used to obtain such information: company's human resources, documentation, intellectual property (inventions, utility models, industrial designs, patents, etc.), technical data carriers, software and others. The choice of source depends on available tools, objectives and potential usefulness of data obtained.
Threats and risks to Information Security
The threat is a potential or actual action aimed at causing material or moral damage to a company or an individual. Naturally, in order to establish the most effective data protection process, it is necessary to understand risks and potential threats that a company will face. It is customary to distinguish three main groups of threats.
Technogenic (related to the malfunction of equipment or technologies of the protected system, as well as the use of specialised technical means and software). These may include the following risks:
-
use of pirated software and circumvention of licences;
-
integration of malicious software (viruses, encryptors, backdoors, blockers, mining programmes, etc.);
-
DDoS attacks;
-
phishing;
-
hardware and software for audio and video surveillance, etc.
Let's look at an example of an Information Security threat caused by human error. For example, the Play ransomware attack on the IT company Xplain in Switzerland, which affected the local railway network and many government agencies. Hackers gained access to more than 1.3 million files, including 65,000 documents belonging to the Swiss Federal Government. Play managed to carry out the Information Security threat through a phishing email containing malware.
Another example from 2010. At that time, the Win32/Stuxnet network worm spread among a large number of private and public computer systems. This virus exploited vulnerabilities in Microsoft Windows (a zero-day vulnerability), intercepting and modifying the information flow between Simatic S7 programmable logic controllers and SimaticWinCC (Siemens) SCADA system workstations. Win32/Stuxnet could be used for industrial espionage and sabotage (its original purpose). It went down in history as the first malware that not only damaged digital data but also caused real physical damage to equipment. The main source of its spread was infected USB drives.
Anthropogenic (related to intentional or accidental disclosure of confidential commercial information):
-
insider leaks;
-
errors in the performance of official duties;
-
actions of unreliable employees.
An example of an anthropogenic threat to the company's security is Colonial Pipeline. It is the largest pipeline system in the United States and the main supplier of gas and petroleum products from the Gulf of Mexico to the entire East Coast. On 7 May 2020, the Colonial Pipeline system was infected with ransomware. As it later turned out, the attack was carried out by a group of hackers called DarkSide. Their goal was to obtain a ransom of $5 million. But even after transferring the funds to the extortionists, the company was unable to quickly restore its business processes. This led to a large-scale crisis in several states and a fuel shortage at the time.
The person responsible on the Colonial Pipeline side was one of its employees, whose password was used in the attack. Using this password to access the VPN service, hackers were able to gain access to the corporate system. The employee had previously used the same password to register for another account, information about which was already available on the Darknet.
Another example: the hacking of Twitter accounts of famous people in July 2020. At that time, hackers managed to publish a link to a message asking for cryptocurrency donations, such as: "Send me 1 BTC and get 2 back". The accounts of Tesla and SpaceX CEO Elon Musk, Amazon founder Jeff Bezos, one of the largest private investors and head of Berkshire Hathaway Warren Buffett, former US President Barack Obama, Google, Apple and many other accounts were hacked.
As a result of the attack, approximately 300 people were affected, who sent just over $110,000 to the specified crypto addresses. This situation also had a negative impact on Twitter itself: irreparable damage was done to its reputation, and the incident caused its share price to fall by 4.5% at one point. The main source of information for fraudsters was a Twitter employee who, according to the hackers themselves, "…literally did everything for them".
Natural disasters (force majeure, natural disasters).

In which areas is Information Security most important?
It is impossible to limit the scope of Information Security. To some extent, unauthorised dissemination of information is harmful in any sphere of human life, the state or a company. However, it is still possible to identify certain industries in which the use of data protection measures is critically important.
These include:
-
critically important state infrastructure and enterprises related to these areas (energy, public safety, defence and state administration facilities);
-
the banking sector and financial organisations (the country's central bank, private and state banking institutions, pension and insurance funds, monetary and credit organisations, etc.);
-
healthcare facilities;
-
transport and logistics complexes (management systems for road, rail, water, air and pipeline transport);
-
facilities ensuring the state's information sovereignty (notarial and legal databases, information agencies and the media).
As we can see, the need for Information Security exists in all major areas of public life and business in a country. There is one rule for determining the need to apply information protection measures at a facility. As a rule, this applies to organisations (whether private or public) whose activities involve the use of large amounts of sensitive confidential data, as well as information that is constantly changing depending on external or internal factors (e.g. banks and exchange rates, air transport and internal schedules, railway timetables, etc.). With such a large amount of changing information, tracking and preventing negative scenarios is the primary task of Information Security.
What Information Security measures are used by IS specialists?
It is customary to distinguish between several types of measures for ensuring Information Security. Each of them provides protection in its own area of responsibility. However, it is impossible to say that the use of one of these measures will be sufficient to prevent and eliminate potential Information Security risks. One of the main principles of protection is comprehensiveness. The more measures a company or individual can include in their security system, the more reliable the entire protection system will be.
Information Security measures are divided into:
-
legal;
-
moral and ethical;
-
organisational and administrative;
-
physical;
-
hardware;
-
software;
-
artificial intelligence (AI).
Let's discuss each measure in more detail.

Legal measures for regulating Information Security
This involves creating and adapting the regulatory framework of a state, international regulators, institutions, etc. to meet needs of a comprehensive, effective and legal approach to Information Security. Today, a large number of regulators are involved in Information Security, even those whose activities are not directly related to this area. The UN Security Council monitors the international agenda and can make recommendations on implementation of iInformation Security systems to various states. This also includes international companies involved in product certification and standardisation. For example, certificates from the International Consortium for Information Systems Security Certification (CISSP) and the International Organisation for Standardisation (ISO) are popular.
Moral and ethical measures for regulating Information Security
These measures include written (codes of ethics, rules of conduct, etc.) and unwritten (personal moral qualities, internal standards of honesty, patriotism, duty) norms regulating human behaviour in a given situation.
Organisational and administrative measures for regulating Information Security
Organisational and administrative measures for protecting information are measures for regulating processes, using labour and material resources, and creating a scheme for interaction between all participants in the information system. The purpose of these measures is to create reasonable and understandable rules of conduct for everyone, aimed at preventing risks to Information Security. An example of such a measure could be a commercial secrecy agreement in a company (preliminary notification of an employee about their responsibility for possessing information within their competence).
Physical measures for regulating Information Security
This is actual physical opposition to violations: installing locks, safes, access control systems, video surveillance, etc.
Hardware measures for regulating Information Security
This is an intermediate stage between physical protection and software protection. Hardware measures, like software measures, become part of the system. These can include tools for protecting voice information (white noise, audio), electronic devices for warning of unauthorised access (USB identifiers, electronic keys, hardware firewalls, etc.). However, mechanical means of countering potential threats are also used — these are independent physical objects that can be quickly removed from the protected system.
Software measures for regulating Information Security
Software measures for ensuring Information Security are aimed at performing the following basic functions: subject identification, system participant authentication, data encryption and processing.
-
DLP (Data Leak Prevention) systems prevent information leaks outside a company and monitor staff for intentional or unintentional disloyal behaviour.
-
An example of such a system is Anexet from Scinero Software Limited. The advantage is that it offers a free 30-day trial period. For more details, follow the link.
SIEM systems (Security Information and Event Management). As the name suggests, this is a software solution for analysing all network activity and responding in real time to potential threats and cyber attacks. -
Cryptography. This is a set of operations for encrypting text that allows all information in the system to be stored by changing its appearance. With the help of cryptography, confidential information becomes inaccessible to potential attackers, as it cannot be read without a special key – a decryptor.
-
Licensed antivirus software.
-
Software firewalls that act as a filter between the World Wide Web and a company's local Internet network. They block incoming traffic according to predefined rules.
-
Proxy servers and VPNs. These two technologies are similar: both are designed to replace your IP address with their own and mask your actual traffic. They differ mainly in terms of implementation cost and availability of encryption (VPN).
-
AI for security systems. In today's world, cybercriminals' speed of learning and adaptation to an ever-changing environment far exceeds the speed at which weapons to combat them can be developed. Only the self-learning mobile system such as artificial intelligence (AI) can keep up with all updates. AI has seen rapid development over the last two years. And while until recently it was only an auxiliary tool in the overall range of Information Security measures, it is now a fully-fledged measure to counter leaks.
IS problems
Of course, such a mobile environment, such as information and ensuring its security, has a number of problems. Let's talk about this now.
-
Data overload
The first problem is the growth in the volume of data that needs to be protected. Every year, the amount of information used grows: the volume of business correspondence, communication on social networks, applications and services used in almost all areas of human life and organisational work increases. This growth is in the hundreds of percent annually. This means that the amount of information that needs to be protected is also increasing. Information Security tools are being adapted to meet this need, but their adaptation is not always directly proportional to the growth in data volumes.
-
Legislation
Today, every state, organisation and individual is left to tackle this task alone – to make their environment safe. In fact, there is no single approach to Information Security, just as there is no common legislation that could solve this problem.
-
Development of crimes
Along with the growth in data volume, the number of ways for data to leak or be maliciously infiltrated has also increased. Criminals adapt much faster than products. Take AI as an example: malicious programmes based on this technology already exist.
Conclusion
Information security is a complex task. It is impossible to create a functioning Information Security tool without taking into account the comprehensiveness and multifaceted nature of this task. Every entity — whether a government, business, or private individual — is free to choose its own path to ensuring Information Security. But they all have one thing in common: in today's world, this issue is of paramount importance, and no one can afford to ignore it.

















