increasing interconnectivity, information is now exposed to a growing number and a wider variety of threats and vulnerabilities. Information can exist in many forms. It can be printed or written on paper, stored electronically, transmitted by post or by using electronic means, shown on films, or spoken in conversation. Whatever forms the information takes, or means by which it is shared or s tored, it should always be appropriately protected. Information security is the protection of information from a wide range of threats in order to ensure business continuity, minimize business risk, and maximize return on investments and business opportunities. Information security is achieved by implementing a suitable set of controls, including policies, processes, procedures, organizational structures and software and hardware functions. These controls need to be established, implemented, monitored, re viewed and improved, where necessary, to ensure that the specific security and business objectives of the organization are met. This should be done in conjunction with other business management processes. Information and the supporting processes, systems, and networks are important business assets. Defining, achieving, maintaining, and improving information security may be essential to maintain competitive edge, cash flow, profitability, legal compliance, and commercial image. Organizations and their information systems and networks are faced with security threats from a wide range of sources, including computer-assisted fraud, espionage, sabotage, vandalism, fire or flood. Causes of damage such as malicious code, computer hacking and denial of service attacks have become more common, more ambitious, and increasingly sophisticated. Information security is important to both public and private sector businesses, and to protect critical infrastructures. In both sectors, information security will function as a n enabler and to avoid or reduce relevant risks. The interconnection of public and private networks and the sharing of information resources increase the difficulty of achieving access control. The trend to distributed computing has also weakened the effectiveness of central, specialist control. Many information systems have not been designed to be secure. The security that can be achieved through technical means is limited, and should be supported by appropriate “If you think technology can solve your management and procedures. Identifying which security problems, then you don’t controls should be in place requires careful understand the problems and you don’t planning and attention to detail. Information understand the technology.” security management requires, as a minimum, participation by all employees in the – Bruce Schneier – Chief Technology organization. It may also require participation Officer of Resilient Systems from shareholders, suppliers, third parties, Lebanese National Security Policy Guidelines v1.7 Page 10 |

Select target paragraph3