BookRags.com Literature Guides Literature
Guides
Criticism & Essays Criticism &
Essays
Questions & Answers Questions &
Answers
Lesson Plans Lesson
Plans
My Bibliography Periodic Table U.S. Presidents Shakespeare Sonnet Shake-Up
Research Anything:        
History | Encyclopedias | Films | News | Create a Bibliography | More... Login | Register | Help
Not What You Meant?  There are 26 definitions for IA.

Information assurance

Print-Friendly
About 3 pages (817 words)

Bookmark and Share Know this topic well? Help others and get FREE products!

Information assurance (IA) is the practice of managing information-related risks. More specifically, IA practitioners seek to protect the confidentiality, integrity, and availability of data and their delivery systems. These goals are relevant whether the data are in storage, processing, or transit, and whether threatened by malice or accident. In other words, IA is the process of ensuring that the right people get the right information at the right time. Information assurance is closely related to information security and the terms are sometimes used interchangeably. However, IA’s broader connotation also includes reliability and emphasizes strategic risk management over tools and tactics. In addition to defending against malicious hackers and code (e.g., viruses), IA includes other corporate governance issues such as privacy, compliance, audits, business continuity, and disaster recovery. Further, while information security draws primarily from computer science, IA is interdisciplinary and draws from multiple fields, including fraud examination, forensic science, military science, management science, systems engineering, security engineering, and criminology, in addition to computer science. Therefore, IA is best thought of as a superset of information security. Information assurance is not just Computer Security because it includes security issues that do not involve computers. The U.S. Government's National Information Assurance Glossary defines IA as:

Measures that protect and defend information and information systems by ensuring their availability, integrity, authentication, confidentiality, and nonrepudiation. These measures include providing for restoration of information systems by incorporating protection, detection, and reaction capabilities.

Contents

Information assurance process

The IA process typically begins with the enumeration and classification of the information assets to be protected. Next, the IA practitioner will perform a risk assessment. This assessment considers both the probability and impact of the undesired events. The probability component may be subdivided into threats and vulnerabilities. The impact component is usually measured in terms of cost. The product of these values is the total risk. Based on the risk assessment, the IA practitioner will develop a risk management plan. This plan proposes countermeasures that involve mitigating, eliminating, accepting, or transferring the risks, and considers prevention, detection, and response. A framework, such as ISO 17799 or ISO/IEC 27002, may be utilized in designing this plan. Countermeasures may include tools such as firewalls and anti-virus software, policies and procedures such as regular backups and configuration hardening, training such as security awareness education, or restructuring such as forming an computer security incident response team (CSIRT) or computer emergency response team (CERT). The cost and benefit of each countermeasure is carefully considered. Thus, the IA practitioner does not seek to eliminate all risks, were that possible, but to manage them in the most cost-effective way. After the risk management plan is implemented, it is tested and evaluated, perhaps by means of formal audits. The IA process is cyclical; the risk assessment and risk management plan are continuously revised and improved based on data gleaned from evaluation.

See also

External links

Documentation

_EMSEC_

  • AFI 33-203, Vol 1, Emission Security (Soon to be AFSSI 7700)
  • AFI 33-203, Vol 3, EMSEC Countermeasures Reviews (Soon to be AFSSI 7702)
  • AFI 33-210, Vol 8, Protected Distributed Systems (Soon to be AFSSI 7703)

_COMPUSEC_

  • AFMAN 33-223, Identification and Authentication (Soon to be AFSSI 8520)
  • AFI 33-202, Vol 6, Identity Management (Soon to be AFSSI 8520)
  • (Biometrics) (Soon to be AFSSI 8521)
  • AFI 33-202, Vol 1, Chapter 5, Access to Information Systems (Soon to be AFSSI 8522)
  • AFI 33-202, Vol 1, Para 3.11, Cross-Domain Solutions (CDS) (Soon to be AFSSI 8540)
  • AFI 33-202, Vol 1, Para 4.2, Network Security (Soon to be AFSSI 8550)
  • AFI 33-137, Ports, Protocols, and Services (PPS) Management (Soon to be AFSSI 8551)
  • AFI 33-230, Information Assurance Assessment and Assistance Program (Soon to be AFSSI 8560)
  • AFI 33-219, Section C, Notice and Consent Procedures (Soon to be AFSSI 8561)
  • AFSSI 5020, Remanence Security (Soon to be AFSSI 8580)

Organizations

Education and certifications

View More Summaries on Information assurance
 
Ask any question on Information assurance and get it answered FAST!
Answer questions in BookRags Q&A and earn points toward
discounted or even FREE Study Guides and other BookRags products!
Learn more about BookRags Q&A
Copyrights
Information assurance from Wíkipedia. ©2006 by Wíkipedia. Licensed under the GNU Free Documentation License. View a list of authors or edit this article.

Article Navigation
Join BookRagslearn moreJoin BookRags




About BookRags | Customer Service | Report an Error | Terms of Use | Privacy Policy