Information security

Information security is the appropriate protection of the confidentiality, integrity and availability of information on paper, in IT systems or in people's heads. § 2 no. 17 of the German BSI Act (BSIG) defines the term in law. According to BSI Standard 200-1, IT security is a subset of it, limited to electronically stored information.

ISMSLast reviewed:

What is information security?

Information security protects the information itself, whatever carries it: its confidentiality, its integrity and its availability. § 2 no. 17 BSIG, the German BSI Act, defines it as "the appropriate protection of the confidentiality, integrity and availability of information" (our translation). The glossary of the BSI's IT-Grundschutz Compendium adds that information may be stored on paper, in IT systems or in people's heads.

A printed contract at reception, a conversation on a train and a database in your own data center therefore all fall within it. Information security is managed through an information security management system (ISMS).

Law and standards define the same core

All the main sources center on confidentiality, integrity and availability; they differ in what they protect and what they add.

SourceTermWhat it says
§ 2 no. 17 BSIGinformation securityappropriate protection of the confidentiality, integrity and availability of information
§ 2 no. 39 BSIGsecurity in information technologycompliance with security standards in, or in the use of, IT systems, components and processes
ISO/IEC 27000, clause 3.28information securitycenters on confidentiality, integrity and availability; a note names four further properties that may apply, including authenticity
BSI Standard 200-1, chapter 2information securityprotection of information of every kind and origin; IT security is a subset of it
Article 6(2) of Directive (EU) 2022/2555security of network and information systemsnames authenticity alongside availability, integrity and confidentiality

The BSIG itself draws the line: no. 17 attaches to the information, no. 39 to safeguards in and around IT systems. According to BSI Standard 200-1, IT security focuses on electronically stored information and its processing. The comparison information security vs. IT security sets the two terms side by side, attribute by attribute.

What does information security deal with?

Information security deals with anything that can impair confidentiality, integrity or availability, including events without an attacker. Chapter 2 of BSI Standard 200-1 gives examples:

  • Fire or water puts storage media and IT systems out of action.
  • After a failed software update, data is altered without anyone noticing.
  • A business process stalls because the only employees who know the application are ill.
  • Confidential documents are passed on by mistake because they were not marked as confidential.

Information security therefore protects every asset in or on which information resides. That includes information and data, the business processes that use them, and the IT systems and rooms where they are processed. It also covers the people with access and the service providers working on your behalf.

Each protection goal is rated separately per asset: a price list can be public and still must not be falsified. The three protection goals and their extensions are explained in the entry on the CIA triad.

Where does the duty to ensure information security come from?

The duty to ensure information security comes from several sources; which one applies depends on sector, size and the data processed (as of October 2026).

Source of the dutyWho is affectedWhat is required
§ 30 BSIG, since December 6, 2025essential and important entities (besonders wichtige and wichtige Einrichtungen), around 29,500 according to the BSIappropriate, proportionate and effective technical and organizational measures; paragraph 2 sentence 2 lists ten minimum measures
Article 32 GDPRanyone processing personal datatechnical and organizational measures for a level of security appropriate to the risk
Regulation (EU) 2022/2554 (DORA), Chapter II, Articles 5 to 16financial entitiesICT risk management
§ 43(1) GmbHG, § 93(1) sentence 1 AktGmanaging directors and management boardsthe care of a prudent businessperson, or of a diligent and conscientious manager
Contracts and tenderssuppliers whose customers require evidencethe evidence agreed in the contract, for example an ISO/IEC 27001 certificate

For essential and important entities, § 38(1) BSIG adds that management must implement the measures under § 30 and oversee their implementation.

Four types of controls under ISO/IEC 27002

Information security controls work on four levels: organizational, people, physical and technological. ISO/IEC 27002:2022 groups its 93 controls into exactly these four.

LevelNumber in ISO/IEC 27002:2022Examples
Organizational37policy, roles, asset inventory, classification, suppliers, incident handling
People8pre-employment screening, confidentiality agreements, awareness
Physical14physical access control, protection of rooms and equipment, disposal of storage media
Technological34access rights, multi-factor authentication, backup, logging, encryption

Which controls a company implements follows from its risk assessment; the catalog is a cross-check that nothing was missed.

An ISMS makes information security manageable

Information security is implemented through an ISMS, a managed cycle rather than individual measures. An ISMS organizes this work in five recurring steps:

  1. Set the scope and adopt an information security policy.
  2. Record assets with their owners in an asset inventory.
  3. Assess protection needs and risks per asset.
  4. Derive controls from risk treatment, each with an owner and a deadline.
  5. Check effectiveness through internal audits, metrics and the management review, and correct deviations.

The full process is described in the guide to ISMS implementation.

How Rizzqo tracks information security per asset

Rizzqo models information security on the assets themselves. Information, processes and services are primary assets; the systems, applications, cloud services and providers that support them sit beneath. Processes and services are rated for confidentiality, integrity and availability, information for confidentiality. Supporting assets inherit only the confidentiality rating and the personal-data flag from the primary assets.

Requirements from ISO/IEC 27001 and ISO/IEC 27002 appear on the assets they apply to, through asset category and subcategory, with an assigned owner. A requirement counts as met only once it is finalized with a name and a timestamp.

Browse all entriesBack to top

Frequently asked questions

See compliance run on your real assets

Rizzqo turns framework requirements into owned tasks on the assets you already have, and prices the risk in real money.

Made in GermanyHosted in your countryMulti-framework