Security
Pronunciation: sih-KYOOR-ih-tee
Definition
Security is the protection of assets and objectives against unauthorized access, harm, manipulation, disclosure, disruption, or loss within a defined operating context. Security combines people, processes, technology, governance, and physical measures to preserve properties such as confidentiality, integrity, availability, authenticity, accountability, safety, and resilience. Controls reduce selected risks within assumptions, while attackers, dependencies, errors, incentives, and environments change. Improving one property can introduce cost, complexity, surveillance, reduced usability, or new concentration risk.
Overview
Security combines people, processes, technology, governance, and physical measures to preserve properties such as confidentiality, integrity, availability, authenticity, accountability, safety, and resilience. Relevant properties depend on the system and stakeholder objectives.
Security is not an absolute state. Controls reduce selected risks within assumptions, while attackers, dependencies, errors, incentives, and environments change. Improving one property can introduce cost, complexity, surveillance, reduced usability, or new concentration risk.
Organizations should define assets, threats, trust boundaries, acceptable risk, control ownership, monitoring, response, and recovery. Assurance requires evidence from testing, operation, incidents, and independent review, followed by adaptation as systems and adversaries evolve. Security decisions should account for customer harm and operational consequences together.
Security is the protection of assets and objectives against unauthorized access, harm, manipulation, disclosure, disruption, or loss within a defined operating context. Security is continuous risk management across technical and organizational systems, requiring explicit objectives, evidence, ownership, response, and adaptation.
A production treatment of Security should test the protection of assets and objectives against unauthorized access, harm, manipulation, disclosure, disruption, or loss within a defined operating context within the relevant asset, decision, or service state. The Security context record for harm, manipulation, and disclosure should preserve source data, configuration or policy version, responsible actor, exception, and outcome. Review of Security should determine whether safeguards addressing harm, manipulation, and disclosure changed exposure in practice, not merely whether a document or setting existed.
Quality review for Security should sample real cases involving harm, manipulation, and disclosure, compare expected and actual outcomes, and track unresolved exceptions until remediation is independently verified.
Key Takeaway
Security is continuous risk management across technical and organizational systems, requiring explicit objectives, evidence, ownership, response, and adaptation.
Sources
- NIST Documentation: Cyberframework — NIST (2026-07-30)
- FATF Documentation: Virtual Assets — FATF (2026-07-30)