Information Security
Information security is the protection of information and information systems against unauthorized access, modification, disclosure, disruption, or destruction.
“The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.”
(Definition reproduced from the ISTQB Glossary. Copyright belongs to ISTQB.)
View the complete ISTQB GlossaryWhat is Information Security?
Information security preserves the confidentiality, integrity, and availability of information through technical, physical, and administrative controls.
CIA triad: Confidentiality, integrity, and availability are core security objectives.
Defense in depth: Multiple layers of security reduce overall risk.
Testing focus: Security testing validates implemented controls.
Real World Example
An online banking login flow is being reviewed after fraud analysts report repeated attempts to discover valid customer accounts.
The concern is not whether ordinary login works; it is how the system behaves when someone intentionally misuses it. Information security points testing toward that hostile or risky behavior.
The tester probes rate limits, error messages, audit events, lockout behavior, and monitoring signals to see whether the system gives attackers useful feedback.
The team strengthens the controls because Information security helps them test the product from the perspective of misuse, not only normal customer journeys.
Practice Questions
Question 1
Which statement BEST describes Information security in the context of ISTQB terminology?
Question 2
A tester needs to explain Information security to a non‑technical stakeholder. Which approach is MOST appropriate?
Test your knowledge with real ISTQB-style questions
You’ve learned Information Security. Test your understanding with topic-specific questions in our Mock Exams.