IT438
The goal of this module is to introduce you to the concept of a critical information asset and to get you to start thinking about the security controls you might assess for a critical information asset.
Organizations typically have lots of physical assets, but not all are critical to the core business of the organization. For example, an office chair is a physical asset. However if the chair were to break or get stolen, it’s doubtful that the impact would be significant. An example of a physical asset that is a little more critical might be an office building. If an organization only had one building and it was destroyed by fire or flood, the impact on the organization would be significant, if not catastrophic.
The same thinking can be applied to information systems. Organizations have several information assets upon which they rely, with some of the information assets being more critical than others. For example, a business that is purely brick and mortar might have a website that is used to provide general information about the business. If that website were to go down, it would have some impact, but it’s doubtful that it would have a critical impact on the business. However if another business is purely online and its website were to go down, the impact would be significant. In the discussion board for this module, you will be generating more examples of a critical information system. You will also be replying to members in your group about the examples they have chosen.
As the critical information assets for an organization are identified, it is also important to determine the appropriate security controls for those assets. Not every control applies to every information asset. Even if a control does apply, the organization’s management may determine that a control is not going to be assessed. One of this module’s questions will ask you to identify five controls that should be assessed for an information asset and to justify why you selected those controls.
As you complete the module’s readings and assignments, one thing to keep in mind is that an information asset is not a computer. The information asset may be stored on a computer, but the computer is NOT the information asset. Step 2 in Introducing Octave Allegro has a good set of definitions that you should refer to.