This blog is a technical one and is addressed to technical and non technical persons.
The main goal is to address security issues, but in a real word IT security should be treated in correlation with the entire environment.
Following capabilities should be protected and assured by security in my opinion:
- The capability of a system to continuously deliver services which depends on the availability of hardware, software and services.
- The capability of a system to prevent unauthorized individuals and processes from accessing data. This concerns the preservation of data confidentiality and integrity.
- The capability of a system to ensure that specific actions and transactions have actually taken place.
- The capability of a system to carry out actions and provide the expected services throughout its life span.
All these capabilities will make a stronger and more secure environment.