CB2500 Chap.10 Information Security and Business Continuity
Information Security and Business Continuity
Three properties that fail separately
Week nine turns the course toward what happens when information fails, and does it from a professional angle: security management sits beside accounting and continuity planning, and the profession named for the work is the information systems auditor, listed in week one alongside project management, business analysis and digital marketing.
Security is usually introduced as three properties, and keeping them apart matters because a case rarely breaks all three. Confidentiality fails when somebody sees what they should not. Integrity fails when a record is changed without authority, which is often worse because nothing looks wrong. Availability fails when the information is intact and unreachable.
The controls differ completely, so naming the property is what makes a proposal relevant.
Four responses, not one
Not every exposure deserves a control, and a report proposing controls for everything has made no management judgement. The standard decision weighs how likely an event is against how badly it would hurt, and produces four responses: reduce, transfer, avoid and accept.
Acceptance is legitimate provided it is written down, dated and owned; an unrecorded acceptance is indistinguishable from not having noticed.
Likelihood is the harder estimate, and only three grounds are defensible in a student report: it has happened here before, it has happened to comparable organisations, or the control that would prevent it is known to be absent.
Evidence rather than intent
The distinctive move in this material is asking what would demonstrate that a control operated.
A policy saying access is reviewed quarterly is intent; a dated record of the last four reviews with names attached is evidence.
Writing every control as a pair, what should happen and what artefact proves it happened, converts a list into an auditable position and costs one clause each.
Continuity is two promises with two bills
Continuity planning asks a narrower question: given that something will eventually stop, how much work may be lost and how long may the service be down.
Those are separate targets and separately priced, and confusing them is the commonest error here. Neither is chosen by a technical team, because both state what the organisation can tolerate. A plan also decays quietly, so the only evidence it works is a test with a date on it; when a case shows a plan that has never been exercised, that absence is a finding rather than an administrative gap.
What this chapter covers
- 01
Confidentiality, integrity and availability as separate failures
- 02
The auditor's question about whether a control operated
- 03
Likelihood against impact
- 04
Reduce, transfer, avoid and accept
- 05
Recording an acceptance so it counts as a decision
- 06
Recovery point against recovery time
- 07
Who sets a continuity target and why
- 08
Testing a plan, and what never means
- 09
Standard processes against local rules across borders
Read an incident onto the right property and the right target
- 3Name the property that failed and rule out the other two.
- 3Identify which continuity target is tested, with a reason.
- 3Give a control and the artefact that evidences it.
Key terms
- Confidentiality
- The property that information is seen only by those entitled to see it.
- Integrity
- The property that a record is changed only by an authorised action, so what is stored can be trusted.
- Availability
- The property that information can be reached when it is needed, independent of whether it is correct.
- Recovery Point
- The amount of work an organisation agrees in advance it can afford to lose in a failure.
- Recovery Time
- The length of time an organisation agrees in advance it can afford a service to be unavailable.
- Risk Acceptance
- A recorded, dated and owned decision to live with an exposure rather than control it.
- Control Evidence
- The artefact showing that a control actually operated during a period, as distinct from the policy requiring it.
Information Security and Business Continuity FAQ
How do I choose between reducing and accepting a risk?
Weigh how likely the event is against how badly it would hurt, and remember that transfer and avoidance are also available. Acceptance is the right answer for a low-impact or unavoidable exposure a small organisation cannot afford to control, but only if it is written down, dated and owned by a named person. Undocumented acceptance reads to an auditor as an unmanaged risk.
What is the difference between the two continuity targets?
One looks backwards from the failure and one forwards. The recovery point is the gap between the last good copy and the moment things stopped, so it measures work lost. The recovery time is the gap between stopping and being usable again, so it measures how long customers notice. Shortening the first costs more frequent copies; shortening the second costs standby capacity.
Why does the course link this material to accounting?
Because accounting exists to make claims about what happened, so integrity failures there do the most damage and the culture of keeping evidence is already present. Learning controls through that lens builds the habit that transfers everywhere: every control has an owner, a frequency and a record, and one with none of those is a sentence in a document.
Exam move
For any organisation you know, write three incidents, one per security property, and check that each is genuinely about a different property rather than the same story retold. Then write two controls with their evidence artefacts beside them, because the artefact column is what the auditing habit actually is.
Finish with the two continuity targets expressed as sentences a manager would sign: we can lose at most this much work, and we can be down at most this long.
Working through Information Security and Business Continuity in CB2500? Sia is AskSia’s AI Information Technology tutor — ask any CB2500 Information Security and Business Continuity question and get a clear, step-by-step explanation grounded in how CB2500 is taught and assessed. Read this chapter free, then take your hardest questions to Sia.