Quiz Entry - updated: 2026.07.30
What are the three pillars of information security?
The three pillars are People, Processes, and Technology — all three must work together for effective security.
* People, Processes and Technology — the three pillars that must work together for effective security. *
| Pillar | Focus | Examples |
|---|---|---|
| People | Human behavior, awareness, skills | Security awareness training, clear roles, background checks |
| Processes | Policies, procedures, workflows | Incident response plans, change management, access reviews |
| Technology | Tools and systems | Firewalls, encryption, IDS/IPS, SIEM, MFA |
Why all three matter:
- Technology alone fails — the best firewall won't stop a social engineering attack
- Processes alone fail — written policies mean nothing if nobody follows them
- People alone fail — good intentions don't help without proper tools and procedures
Common mistake: Organizations over-invest in technology while underinvesting in people and processes. Studies show that human factors are involved in the majority of security breaches.
Tip: When evaluating any security measure, ask: "Does this address people, process, or technology?" A mature security program addresses all three.