Information security is the practice of protecting information so that it stays confidential, remains accurate and is available when needed. These three properties, confidentiality, integrity and availability, are known as the CIA triad. Every requirement in ISO 27001 ultimately exists to protect one or more of them.
What counts as information?
Information is any data with value to the organization, regardless of form. It lives in databases and file shares, but also in contracts on paper, in conversations, in the heads of experienced employees, and in transit between systems. This breadth matters: a security programme that only looks at IT systems misses entire categories of valuable information. ISO 27001 therefore speaks of information and other associated assets, meaning the systems, devices, facilities and people that store, process or transmit it.

The CIA triad
The three protection goals give every security discussion a common language. A useful habit is to ask, for any incident or control, which of the three it concerns.
Property | Meaning | Example of a breach |
|---|---|---|
Confidentiality | Information is accessible only to those authorized | A payroll export shared with the wrong distribution list |
Integrity | Information is accurate and complete | An attacker changes the bank details on a supplier invoice |
Availability | Information is accessible when required | Ransomware encrypts the file server before month-end closing |
The three goals can pull against each other. Encrypting everything strengthens confidentiality but can threaten availability if key management fails. Balancing them for each asset is a risk decision, not a technical default, and that is precisely what a management system is for.
Threats, vulnerabilities and risk
Three further terms carry precise meanings, and using them precisely keeps risk discussions honest.
Term | Definition | Example |
|---|---|---|
Threat | A potential cause of an unwanted incident | Phishing campaigns targeting finance staff |
Vulnerability | A weakness that a threat can exploit | No second approval step for changing payment details |
Risk | The effect of uncertainty on objectives, assessed by likelihood and consequence | Likely fraudulent payment with significant financial impact |
A threat without a matching vulnerability produces little risk, and a vulnerability nobody can reach may be acceptable. Risk emerges from the combination, which is why ISO 27001 requires a structured risk assessment rather than a list of fears.
Information security, cybersecurity and data protection
The three terms overlap but are not interchangeable. Information security covers information in every form, digital and physical. Cybersecurity is the subset concerned with digital systems and networks. Data protection is a legal domain focused on personal data, in Europe governed by the GDPR. An ISMS supports all three, but certification against ISO 27001 is not by itself proof of GDPR compliance, a claim auditors and regulators both reject.
How ISO 27001 builds on these fundamentals
ISO 27001 takes these concepts and makes them operational. Assets and their value inform the asset inventory, threats and vulnerabilities feed the risk assessment, and the CIA triad defines what “secure” means for each asset. The next article explains the vehicle that holds this together: the management system.
Frequently asked questions
Is cybersecurity the same as information security?
No. Cybersecurity concerns digital systems and networks. Information security is broader and includes paper records, physical access and human factors. ISO 27001 addresses the broader discipline.
What is the CIA triad?
The three protection goals of information security: confidentiality, integrity and availability. Every security control serves at least one of them.
Why do paper documents matter in ISO 27001?
Because the standard protects information in every form. A contract in an unlocked cabinet is as much an information security concern as an unpatched server.

