Security describes measures, principles and processes to protect information, systems and infrastructure from threats and misuse. It includes organizational policies, technical controls and continuous monitoring. The goal is to ensure confidentiality, integrity and availability across the full lifecycle while balancing risk and usability.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What you need to understand to reason about a domain.
Security protects information, systems, and processes from unauthorized access, alteration, outage, and misuse.
Security developed as an umbrella term for organizational and technical protection work in information processing and communications. The OWASP Cheat Sheet Series collects practical application patterns.
Security connects goals such as confidentiality, integrity, and availability with risks, responsibilities, and controls. Effectiveness spans the lifecycle and must be balanced with usability, cost, and changing threats.
Protection is a combination of people, processes, and technology.
Risks are assessed and reduced through appropriate controls.
Goals and controls must fit the system and its threat landscape.
Security provides the frame for assessing protection needs, risks, and controls in technical and organizational decisions.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.