Five myths that are popular in India about Information Security:-
Most of the students in India think that studying information security is nothing but learning ethical hacking. This is a very popular myth among youngsters.The reality is quite different, Information security take care of technology and compliance both, these includes information security audit of different security standards like PCI-DSS and ISO 27001 etc. It also includes things like Data Protection Act, Sarbanes-Oxley Act, IT Act 2000 etc. Vulnerability assessment and penetration testing is very popular ingredient of information security. To know more visit SANS Institute.
When i was in first year of my engineering schools and got to know about Vulnerability Assessment and Penetration Testing(VAPT) i thought it is just about hacking with technology, but the truth is that vulnerability assessment can be done through social engineering, knowing about the organization etc. Penetration testing is also possible through social engineering .
3. To work in the field of information security one have to be a technologist.
One can be a lawyer, consultant, teacher, etc. There are various different opportunity that are offered in the field.
4. Information security is only required if technology is used.
Even if a company does not have any electronic equipments then also it need to secure its information and most of these organization do that by complying with with different international security standards.
5. I have spent a big part of my revenue in information security and i am now fully protected.
Mark my words that follows, absolute security is not possible, the only thing that an organization and people can do is, raise the bar. If Somebody says that he will provide your company an absolute security, the man is lying.
Most of the students in India think that studying information security is nothing but learning ethical hacking. This is a very popular myth among youngsters.The reality is quite different, Information security take care of technology and compliance both, these includes information security audit of different security standards like PCI-DSS and ISO 27001 etc. It also includes things like Data Protection Act, Sarbanes-Oxley Act, IT Act 2000 etc. Vulnerability assessment and penetration testing is very popular ingredient of information security. To know more visit SANS Institute.
2. Vulnerability assessment and Penetration testing is only about technology.
When i was in first year of my engineering schools and got to know about Vulnerability Assessment and Penetration Testing(VAPT) i thought it is just about hacking with technology, but the truth is that vulnerability assessment can be done through social engineering, knowing about the organization etc. Penetration testing is also possible through social engineering .
3. To work in the field of information security one have to be a technologist.
One can be a lawyer, consultant, teacher, etc. There are various different opportunity that are offered in the field.
4. Information security is only required if technology is used.
Even if a company does not have any electronic equipments then also it need to secure its information and most of these organization do that by complying with with different international security standards.
5. I have spent a big part of my revenue in information security and i am now fully protected.
Mark my words that follows, absolute security is not possible, the only thing that an organization and people can do is, raise the bar. If Somebody says that he will provide your company an absolute security, the man is lying.
Comments
Post a Comment