what is information security



Information Security—Safeguarding information against unauthorized disclosure; or, the result of any
system of administrative policies and procedures for identifying, controlling, and protecting from
unauthorized disclosure, information the protection of which is authorized by Executive Order or
statute.
Information Security Governance—The management structure, organization, responsibility and
reporting processes surrounding a successful information security program.
Information Security Program—The overall process of preserving confidentiality, integrity and
availability of information.
Information Security Service—A method to provide some specific aspect of security. For example,
integrity of transmitted data is a security objective, and a method that would achieve that is
considered an information security service.