Cybersecurity is the discipline and practice of protecting digital systems, networks, services, and information against unauthorized access, disruption, alteration, or destruction. It combines technical safeguards with organizational policies, human expertise, and risk management. Its scope includes individual computers, enterprise networks, services delivered over the Internet, and digitally controlled physical equipment. Protection involves not only preventing attacks but also detecting compromises, responding to incidents, and restoring essential operations. (niccs.cisa.gov)
Objectives and scope
Cybersecurity overlaps with information security, which protects information and information systems. A central model is the confidentiality, integrity, and availability triad, often called the CIA triad. Confidentiality concerns preventing unauthorized disclosure; integrity concerns preventing improper alteration or destruction; and availability concerns timely, reliable access by authorized users. These objectives can require different safeguards: keeping a document secret does not necessarily ensure that it is accurate or accessible. (csrc.nist.gov)
Security also involves establishing identities, enforcing permissions, and maintaining records of significant actions. It is related to, but distinct from, data privacy. Security controls can protect personal information against unauthorized access, while privacy also concerns how information is collected, processed, and used. A system may therefore require both security and privacy controls rather than treating either as a substitute for the other. (csrc.nist.gov)
Threats, vulnerabilities, and risk
A threat is a potential cause of harm, whereas a vulnerability is a weakness that a threat can exploit. Risk assessment considers the likelihood of harmful events and their consequences for systems, organizations, or individuals. Threats are not limited to deliberate attacks: mistakes, equipment failures, and other disruptions can also affect security objectives. (niccs.cisa.gov)
Common attack categories include malware, malicious software that compromises systems, and ransomware, which can deny access to data through encryption. Ransomware operations may also steal information and threaten disclosure. Phishing uses deceptive communications to induce recipients to reveal information or perform unsafe actions; it is a form of social engineering, which targets human behavior rather than only technical weaknesses. Compromised credentials and exposed remote-access services can provide attackers with an initial foothold. (cisa.gov)
A denial-of-service attack targets availability by exhausting resources or otherwise preventing legitimate access. Distributed denial-of-service attacks involve multiple sources of attack traffic. Their effects differ from information theft: a service can become unusable even when confidential records have not been disclosed. (cisa.gov)
Protective technologies and architecture
Access control determines which users, devices, or processes may use particular resources. Authentication establishes confidence in an identity, while authorization determines permitted actions. Multifactor authentication requires two or more distinct verification factors, reducing dependence on a password alone. The principle of least privilege restricts access to what is necessary for an assigned task. (csrc.nist.gov)
Cryptography supports protections such as encryption and integrity verification. Its effectiveness depends on implementation and the handling of cryptographic keys. Other controls include network filtering, secure configurations, software updates, and isolation of resources. Defense in depth combines complementary safeguards so that protection does not depend entirely on a single mechanism. These controls address different failure modes rather than providing interchangeable guarantees. (csrc.nist.gov)
Zero trust architecture rejects implicit trust based solely on network location or ownership of a device. Access decisions instead evaluate the requesting subject, device, resource, and relevant policy. NIST’s 2020 description emphasizes protecting resources rather than assuming that everything within a network boundary is trustworthy. This approach is relevant to distributed environments that include remote users and cloud computing. (csrc.nist.gov)
Secure development and assurance
Cybersecurity is also part of software engineering. Secure development incorporates security requirements and practices throughout the software life cycle rather than relying exclusively on defenses added after deployment. NIST’s Secure Software Development Framework describes practices intended to reduce vulnerabilities in released software, limit the consequences of remaining weaknesses, and address root causes to prevent recurrence. (csrc.nist.gov)
Security assurance concerns the evidence that safeguards function as intended. Reviews, testing, and assessments examine both control implementation and effectiveness. Penetration testing is an authorized assessment that attempts to identify exploitable weaknesses under defined conditions. Its findings concern the systems and conditions tested; it is one assessment technique within a broader program of security evaluation. (csrc.nist.gov)
Detection, response, and recovery
Detection uses observations such as system logs, suspicious activity, and changes in resource usage to identify possible incidents. Incident response coordinates investigation, containment, remediation, and communication. It requires preparation and defined responsibilities rather than beginning only after an attack is discovered. NIST’s incident-response guidance, published in April 2025, places these activities within continuous cybersecurity risk management. (cisa.gov)
Recovery restores affected data and services while addressing the conditions that enabled the incident. Backups support restoration, but their usefulness depends on their availability and integrity. Offline or otherwise protected copies can resist attacks that delete or encrypt accessible backups. Restoration testing establishes whether recovery procedures work in practice. Restoring encrypted files does not itself reverse an earlier disclosure of stolen information. (cisa.gov)
Governance and organizational responsibility
Cybersecurity governance establishes policies, responsibilities, oversight, and acceptable levels of risk. NIST’s Cybersecurity Framework version 2.0, released on February 26, 2024, organizes outcomes into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. These are concurrent, continuous functions, not a sequence completed once. The framework describes desired outcomes without prescribing one universal technical implementation. (nist.gov)
Organizational programs also address personnel training, supplier relationships, asset inventories, and dependencies between services. In cloud environments, responsibility is divided between provider and customer according to the service model and contractual arrangements. Understanding those boundaries remains part of security management even when infrastructure is operated by another organization. (nist.gov)