Designing Information Security
摘要
Criminals and spies concentrate on stealing, modifying or destroying financial account information, trade secrets, and internal organization data. This chapter is all about protecting information assets via the three goals of security, CIA: confidentiality, integrity, and availability. Two additional requirements that may apply include legal and privacy liability. We achieve these goals by classifying information assets and then defining how each class of assets should be protected. In addition, authentication, authorization and accountability requires an evaluation of roles, access control, and associated security technologies.