Page 71

The University of Sydney Page 261. Briefly describe the three principles of data security in the context of ensuring information systems security of technical systems.–An organization need to ensure Confidentiality, Integrity and Availability of Hardware, Software and Data. –We need to ensure that confidentiality, integrity and availability are preserved in a technical system by implementing proper/cost effective technical controls that adhere with the formal system–Confidentiality: Information and data stored in an information system should be disclosed only to the people with a ‘Need to Know’.–Example: Employee is only allowed to see his own payroll information. Manager can see the payroll information of employees under him that are relevant for his responsibilities (Approve pay increases)–Organizational software system should implement proper authentication and access control mechanisms to grant the above facilities to designated employees.