(1)
Information security— The term “information security” means protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide—
(A)
integrity, which means guarding against improper information modification or destruction, and includes ensuring information nonrepudiation and authenticity;
(B)
confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information;
(C)
availability, which means ensuring timely and reliable access to and use of information; and
(D)
authentication, which means utilizing digital credentials to assure the identity of users and validate their access.
(2)
Information system— The term “information system” means any equipment or interconnected system or subsystems of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information, and includes—
(A)
networks and computers and other network-enabled devices;
(C)
software, firmware, and related procedures;
(D)
services, including support services; and