What is information security?
Information security protects the information itself, whatever carries it: its confidentiality, its integrity and its availability. § 2 no. 17 BSIG, the German BSI Act, defines it as "the appropriate protection of the confidentiality, integrity and availability of information" (our translation). The glossary of the BSI's IT-Grundschutz Compendium adds that information may be stored on paper, in IT systems or in people's heads.
A printed contract at reception, a conversation on a train and a database in your own data center therefore all fall within it. Information security is managed through an information security management system (ISMS).
Law and standards define the same core
All the main sources center on confidentiality, integrity and availability; they differ in what they protect and what they add.
| Source | Term | What it says |
|---|---|---|
| § 2 no. 17 BSIG | information security | appropriate protection of the confidentiality, integrity and availability of information |
| § 2 no. 39 BSIG | security in information technology | compliance with security standards in, or in the use of, IT systems, components and processes |
| ISO/IEC 27000, clause 3.28 | information security | centers on confidentiality, integrity and availability; a note names four further properties that may apply, including authenticity |
| BSI Standard 200-1, chapter 2 | information security | protection of information of every kind and origin; IT security is a subset of it |
| Article 6(2) of Directive (EU) 2022/2555 | security of network and information systems | names authenticity alongside availability, integrity and confidentiality |
The BSIG itself draws the line: no. 17 attaches to the information, no. 39 to safeguards in and around IT systems. According to BSI Standard 200-1, IT security focuses on electronically stored information and its processing. The comparison information security vs. IT security sets the two terms side by side, attribute by attribute.
What does information security deal with?
Information security deals with anything that can impair confidentiality, integrity or availability, including events without an attacker. Chapter 2 of BSI Standard 200-1 gives examples:
- Fire or water puts storage media and IT systems out of action.
- After a failed software update, data is altered without anyone noticing.
- A business process stalls because the only employees who know the application are ill.
- Confidential documents are passed on by mistake because they were not marked as confidential.
Information security therefore protects every asset in or on which information resides. That includes information and data, the business processes that use them, and the IT systems and rooms where they are processed. It also covers the people with access and the service providers working on your behalf.
Each protection goal is rated separately per asset: a price list can be public and still must not be falsified. The three protection goals and their extensions are explained in the entry on the CIA triad.
Where does the duty to ensure information security come from?
The duty to ensure information security comes from several sources; which one applies depends on sector, size and the data processed (as of October 2026).
| Source of the duty | Who is affected | What is required |
|---|---|---|
| § 30 BSIG, since December 6, 2025 | essential and important entities (besonders wichtige and wichtige Einrichtungen), around 29,500 according to the BSI | appropriate, proportionate and effective technical and organizational measures; paragraph 2 sentence 2 lists ten minimum measures |
| Article 32 GDPR | anyone processing personal data | technical and organizational measures for a level of security appropriate to the risk |
| Regulation (EU) 2022/2554 (DORA), Chapter II, Articles 5 to 16 | financial entities | ICT risk management |
| § 43(1) GmbHG, § 93(1) sentence 1 AktG | managing directors and management boards | the care of a prudent businessperson, or of a diligent and conscientious manager |
| Contracts and tenders | suppliers whose customers require evidence | the evidence agreed in the contract, for example an ISO/IEC 27001 certificate |
For essential and important entities, § 38(1) BSIG adds that management must implement the measures under § 30 and oversee their implementation.
Four types of controls under ISO/IEC 27002
Information security controls work on four levels: organizational, people, physical and technological. ISO/IEC 27002:2022 groups its 93 controls into exactly these four.
| Level | Number in ISO/IEC 27002:2022 | Examples |
|---|---|---|
| Organizational | 37 | policy, roles, asset inventory, classification, suppliers, incident handling |
| People | 8 | pre-employment screening, confidentiality agreements, awareness |
| Physical | 14 | physical access control, protection of rooms and equipment, disposal of storage media |
| Technological | 34 | access rights, multi-factor authentication, backup, logging, encryption |
Which controls a company implements follows from its risk assessment; the catalog is a cross-check that nothing was missed.
An ISMS makes information security manageable
Information security is implemented through an ISMS, a managed cycle rather than individual measures. An ISMS organizes this work in five recurring steps:
- Set the scope and adopt an information security policy.
- Record assets with their owners in an asset inventory.
- Assess protection needs and risks per asset.
- Derive controls from risk treatment, each with an owner and a deadline.
- Check effectiveness through internal audits, metrics and the management review, and correct deviations.
The full process is described in the guide to ISMS implementation.
How Rizzqo tracks information security per asset
Rizzqo models information security on the assets themselves. Information, processes and services are primary assets; the systems, applications, cloud services and providers that support them sit beneath. Processes and services are rated for confidentiality, integrity and availability, information for confidentiality. Supporting assets inherit only the confidentiality rating and the personal-data flag from the primary assets.
Requirements from ISO/IEC 27001 and ISO/IEC 27002 appear on the assets they apply to, through asset category and subcategory, with an assigned owner. A requirement counts as met only once it is finalized with a name and a timestamp.