Quiz Entry - updated: 2026.07.30
What are the "three pillars" on which information security is built?
Technology, processes, and people — security fails if any one of them is neglected.
* Technology, Processes and People each hold up information security; neglect one pillar and the structure fails. *
| Pillar | Typical action |
|---|---|
| Technology (Technik) | buy & configure (firewalls, crypto, IDS) |
| Processes (Prozesse) | define & control (policies, procedures, reviews) |
| People (Mitarbeitende) | raise awareness & train |
Why all three: the strongest firewall won't help if an employee hands over their password to a caller (people), or if nobody ever reviews the firewall rules (process). Attackers probe for the weakest pillar — and it's very often the human one.
Tip: "You can't buy security." Two of the three pillars are organisational, not technical.
Go deeper:
Information security (Wikipedia) — shows the three pillars in action — technical, administrative/process, and the human factor as the most vulnerable point.
NIST glossary: information security — the canonical NIST definition tying protection to confidentiality, integrity and availability.