Introduction to Information Security and Cybersecurity

John T. Bandler, Antonia Merzon · 2020

This chapter summarizes how computers, networks, and technology work, with an eye towards understanding how cybercrimes are committed and investigated, and the technical aspects of obtaining digital evidence. It focuses on information security basics, the controls and defenses that private and government organizations put in place to prevent cybercrime, and how cybercriminals might circumvent the controls. The field of information security centers on protecting an organization’s information assets from a broad range of threats, including cybercrime, natural disaster, brick-and-mortar burglary, and social engineering. Authentication is a technical control that enforces administrative rules about access to data. It is one of the most widely used information security methods and a familiar one to most users. The Center for Internet Security, a non-profit organization dedicated to developing and promoting best practice solutions for cyber defense, maintains the Critical Security Controls, 20 actions that enable organizations to holistically address information security.

Read the paper · More papers on PaperTik