在 “互联网 +” 被广泛提及的今天,安全问题也越来越多的受到人们关注,然而很多人对于 “信息安全”、“数据安全”、“网络安全” 的概念并不是很清楚。我们汇总了官方机构给这三者的定义,还有知乎专业人士的独到见解,来给大家详细解释一下这三者间的区别与联系。




目前,信息安全(InformaTIon security)常见的定义有:

1. 美国联邦政府的定义


2. 国际标准化组织(ISO)定义


3. 我国信息安全国家重点实验室的定义


4. 信息科学研究领域的定义





网络安全(Network security)不仅包括网络信息的存储安全,还涉及信息的产生、传输和使用过程中的安全。



从两者的定义可看出,信息安全与网络安全有很多相似之处,两者都对信息(数据)的生产、传输、存储和使用等过程有相同地基本要求,如可用性、保密性、完整性和不可否认性等。但两者又有区别,不论是狭义的网络安全 —— 网络上的信息安全,还是广义的网络安全都是信息安全的子集。












2004 年左右,到处网络大建设,结构就是星形网络,没有任何安全域可言,人员以网络工程师为主。黑客入侵后,网络工程师承担了安全工程师的角色,并且理所当然的想到黑客是从网络入侵的,那么那段时间的安全视角为网络。

07 年左右,黑客开始以 “业务 “作为主要入侵和修改的目标,网络上开始划分安全域,保障业务的安全提上日程,有了专门的安全工程师,但仅仅是安全产品部署运维。

10 年以后,各种脱裤开始了,黑客将目标瞄准 “数据”,那么安全从一开始的网络入侵转变为数据安全保障。

从安全产品方面可以看到信息安全的发展路线了,以前的时候只有防火墙、IDS、主机防病毒还在收费,其他安全产品尚没有成熟的产品形态。后来有了 IPS、终端防护、网络防病毒、流量清洗等系统。现在有数据库审计,各种 web 防护。

3 个专有名词基本上代表了从一开始的头痛医头,脚痛医脚,发展到现在的以数据安全为导向,未来随着数据承载方和攻击入侵的不断变化或许还有更加新颖的专有名词出现。





数据安全是侧重于一个 “静态” 的数据安全状态。而网络安全偏向于 “动态” 安全,即信息传递过程中的安全。

“数据” 是组成信息的基本元素之一,数据安全是信息安全的 “核安全”。通过保证数据的安全,从而可实现保证信息安全。





















Cybersecurity vs Network Security vs Information Security

网络安全 vs 网络安全 vs 信息安全

Last Updated: 06 Apr, 2022

The security of a computer network is a crucial task. It is a process of ensuring confidentiality and integrity. A system is said to be secure if its resources are used and accessed as intended under all the circumstances, but no system can guarantee absolute security from several of various malicious threats and unauthorized access.

In this article, we will see the difference between Cybersecurity vs Network Security vs Information Security.

Cyber Security: 网络安全:

Cybersecurity is the method of protecting systems, networks, and programs from digital attacks. Cybersecurity involves techniques that help and secure various digital components Networks, data, and computer systems from Unauthorized digital access. There are multiple ways to implement cyber security depending on the kind of network you are connected to and the type of cyber-attacks you are prone to. Common Cyber Security Risks:

  • Social engineering 社会工程
  • Brute force 蛮 力
  • Baiting 引诱
  • Ransomware 勒索软件

Network Security: 网络安全:

Network Security is the method of protecting the usability and integrity of your network and data. It includes both hardware and software terminologies. Effective network security manages access to the network. It targets a variety of threats and stops them from entering or spreading on your network. Common Network Security Risks:

  • Viruses, worms, and trojans

  • Denial of Service (DOS) attack
    拒绝服务 (DOS) 攻击

  • Zero-day attacks


Information Security: 信息安全:

Information security is the measures taken to protect the records from unauthorized entry and use. It gives confidentiality, integrity, and availability. Information Security is the superset that contains cyber security and network safety. it is vital for any enterprise or firm that works on a large scale. data can be electronic or physical. Common Information Security Risks:
信息安全是保护记录免遭未经授权的访问和使用的措施。它提供机密性、完整性和可用性。信息安全是包含 Cyber Security 和 Network Safety 的超集。它对于任何大规模运作的企业或公司都至关重要。数据可以是电子的或物理的。常见的信息安全风险:

  • Access 访问
  • Destruction 破坏
  • Availability 可用性

Information Security vs Cyber Security vs Network Security

Difference Between Cyber Security, Network Security, and Information Security:


S.No.Cyber SecurityNetwork SecurityInformation Security
01.Cybersecurity is the method of protecting systems, networks, and programs from digital attacks. 网络安全是保护系统、网络和程序免受数字攻击的方法。Network Security is the method of protecting the usability and integrity of your network and data. 网络安全是保护网络和数据的可用性和完整性的方法。Information security is the measures taken to protect the records from unauthorized entry and use. 信息安全是保护记录免遭未经授权的访问和使用的措施。
02.Cyber Security is a subpart of Information Security. 网络安全是信息安全的一个子部分。Network Security is a subpart of Cyber Security. 网络安全是网络安全的一个子部分。Cyber Security & Network Security comes under Information Security. 网络安全和网络安全属于信息安全。
03.It protects anything in the cyber area. 它可以保护网络区域中的任何东西。It protects anything in the network area. 它可以保护网络区域中的任何内容。Information security is for information irrespective of the space. 信息安全适用于与空间无关的信息。
04.It deals with protection from cyber attacks. 它处理针对网络攻击的保护。It deals with protection from DOS (Denial of Service) attacks. 它处理对 DOS(拒绝服务)攻击的保护。It deals with the security of data from any kind of threat. 它处理来自任何类型威胁的数据安全。
05.Cyber security attacks against cybercrime and cyber fraud. 针对网络犯罪和网络欺诈的网络安全攻击。Network Security attacks against trojans. 针对特洛伊木马的网络安全攻击。Information Security attacks against unauthorized access, disclosure modification, and disruption. 针对未经授权的访问、披露修改和中断的信息安全攻击。
06.Cyber security ensures the security of the entire digital data. 网络安全确保整个数字数据的安全。Network security only ensures the security of transit data. 网络安全只能保证传输数据的安全。Information security ensures the protection of transit and digital data. 信息安全可确保对传输和数字数据的保护。
07.It deals with the security of the data resting. 它处理数据静止的安全性。It secures data traveling across the network by terminals. 它保护通过终端在网络上传输的数据。It gives integrity, confidentiality, and availability. 它提供完整性、机密性和可用性。
08.Common Cyber Security Risks: 常见的网络安全风险: Social engineering 社会工程 Brute force 蛮 力 Baiting 引诱 Ransomware 勒索软件Common Network Security Risks: 常见的网络安全风险: Viruses, worms, and trojans 病毒、蠕虫和特洛伊木马 Denial of Service (DOS) attack 拒绝服务 (DOS) 攻击 Zero-day attacks 零日攻击Common Information Security Risks: 常见的信息安全风险: Access 访问 Destruction 破坏 Availability 可用性


Information security vs cyber security vs network security: What are the differences?

信息安全 vs 网络安全 vs 网络安全:有什么区别?

By Zach Marzouk, Keumars Afifi-Sabet

last updated October 16, 2023

A guide to the essential differences between information, network, and cyber security and the basic tenets of each


Cyber attacks have become par for the course for enterprises and small and medium-sized businesses (SMBs) over the last couple of decades.

在过去的几十年里,网络攻击已成为企业和中小型企业 (SMB) 的常态。

The prospect of a cyber security incident – which may range from a minor malware infection to a major ransomware attack, with the likes of phishing and social engineering in between – is close to certain for many organizations. This is why maintaining and iterating on a strong security posture is essential across modern businesses.


But security isn’t straightforward and there are different pillars that all come together to form an organization’s outlook. Indeed, information security, cyber security, and network security are all different pillars businesses need to pay attention to, which ensures there aren’t any holes that cyber criminals can exploit. There are different aspects of your business that you need to protect, and slightly different schools of thought around each one – including which particular cyber security skills are required.


It can be easy to conflate these categories of security, which may come to complicate matters when devising a comprehensive business security strategy – so it’s important to know what each school refers to and what each entails. That’s why we’ve put together a quick guide on the differences between information security, cyber security and network security, so you know exactly what your business needs when keeping the hackers out.


What is information security?


Information security, also known as InfoSec, largely centers around preventing unauthorized access to critical data or personal information your organization stores. It is the “protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability,” according to the US Computer Science Resource Center (CSRC). Information security also involves three categories: confidentiality, integrity, and availability.

信息安全,也称为 InfoSec,主要围绕防止未经授权访问您的组织存储的关键数据或个人信息。根据美国计算机科学资源中心 (CSRC) 的说法,它是“保护信息和信息系统免受未经授权的访问、使用、披露、中断、修改或破坏,以提供机密性、完整性和可用性”。信息安全还涉及三个类别:机密性、完整性和可用性。

  • Confidentiality: Ensuring sensitive information isn’t disclosed to unauthorized users while making sure that authorized users have access to it


  • Integrity: Making sure that the data is accurate and complete. Here, the information shouldn’t be edited by anyone who isn’t authorized to access it


  • Availability: Data needs to be available when it’s needed. For example, a denial of service attack (DoS) could prevent this from happening

    可用性:数据需要在需要时可用。例如,拒绝服务攻击 (DoS) 可以防止这种情况发生

There are also several industry standards organizations must adhere to if following this triad, including maintaining password strength, using antivirus software, deploying access controls, security awareness training, and more.


Organizations can meet their information security standards by implementing a strict risk management process. It should identify information, related assets, and the threats and impact of unauthorized access. It should also monitor activities and make adjustments to address any new issues or improvements that have emerged, as well as evaluate any risks to the organization.


What is cyber security?


This is the process your organization must follow to be aware of the latest and emerging cyber security threats and trends – and to protect itself in light of the changing cyber security landscape. Having a healthy cyber security posture involves adopting policies such as zero trust, and using new tools and technologies to fight prospective threats where appropriate, as well as maintain compliance. Additionally, all staff within the organization must stick to these policies to make sure the business is fully protected.

这是您的组织必须遵循的流程,以了解最新和新兴的网络安全威胁和趋势,并在不断变化的网络安全形势下保护自己。拥有健康的网络安全态势包括采用 零信任 等策略,并在适当的情况下使用新工具和技术来应对潜在威胁,并保持合规性。此外,组织内的所有员工都必须遵守这些政策,以确保企业得到充分保护。

As threats evolve, security policies need to be continuously evaluated and updated if need be. Your hardware and software – including endpoints and operating systems – for example, should be functional and secure to the best of your knowledge, but should also be periodically updated and refreshed. Software that you need to continuously assess includes security services, endpoint management tools, or even cloud services.


It’s also key to ensure staff follow any policies and procedures you put in place. Your business could have the best security tools out there, but it makes no difference if employees continue to use their own devices without IT’s knowledge to access data. You might also have an extensive antivirus product in force, but you must still ensure employees are aware of the dangers of phishing emails.

确保员工遵守您制定的任何政策和程序也很关键。您的企业可能拥有最好的安全工具,但如果员工在 IT 不知情的情况下继续使用自己的设备来访问数据,那将没有任何区别。您可能还拥有广泛的防病毒产品,但您仍必须确保员工了解网络钓鱼电子邮件的危险。

What is network security?


Network security spans how an organization protects the usability and integrity of its network and data. This field includes both hardware and software involved in a network and aims to prevent a variety of threats from entering the business’ networks or spreading through it.


It works by combining a number of defensive layers at the edge, and within the network perimeter. As you may assume, different policies and controls are available in each security layer. For example, authorized users must be able to access network resources, where it’s required for their specific roles, such as in a least privilege access regime, while bad actors must be blocked from carrying out any nefarious actions.


Network security is essential for all organizations as it directly affects their ability to safely deliver services or products to employees and customers. It doesn’t matter if it’s enterprise applications or accessing a remote desktop, ensuring the protection of data and apps on your network is vital for your business, as well as securing your reputation.


What is the difference between information security and cyber security?


These two terms are sometimes used interchangeably, so it’s important to understand the differences between them. While information security is the protection of your data from any unauthorized access, cyber security is protecting it from unauthorized access specifically in the online realm.


The cyber security skills your business needs


Who should take ownership of your cyber security strategy?


For example, cyber security centers around preventing ransomware attacks, spyware, or compromised social media accounts, for example. An example of information security is implementing controls for intrusion detection systems or making sure hard-copy files are locked down. Chief information security officers (CISOs) need to understand and identify whether any information is confidential or critical to the organization and whether it might be targeted by hackers.

例如,网络安全以防止勒索软件攻击、间谍软件或受损的社交媒体帐户为中心。信息安全的一个例子是实施入侵检测系统的控制或确保硬拷贝文件被锁定。 首席信息安全官 (CISO) 需要了解和识别任何信息对组织来说是否机密或关键,以及它是否可能成为黑客的目标。

Some people might ask which is more important but these two areas go hand-in-hand. Your organization must have clear policies and procedures around how to deploy both forms of defense – not just one. Both are continuously evolving too. Ultimately, your business must understand, first, what and where the most sensitive data lies, and secondly, which specific measures it’s putting in place to protect that data.


Information security vs network security: What’s the difference?


Information security protects information from unauthorized users, data modification, and access. Network security, on the other hand, must protect data flowing over a particular network. While network security focuses purely on the network, information security is concerned with information overall, irrespective of where it’s located.


For example, when it comes to attacks, network security involves protecting your network from specific threats like DDoS attacks, trojans, zero-day attacks, and spyware. Information security, meanwhile, involves protecting the data from leakage or access without permission, no matter the type of threat or the data’s location.

例如,在攻击方面,网络安全涉及保护您的网络免受 DDoS 攻击、木马、零日攻击和间谍软件等特定威胁。同时,信息安全涉及保护数据免遭泄露或未经许可的访问,无论威胁类型或数据位置如何。

Cyber security vs networking security: What’s the difference?


It isn’t always clear where one begins and ends, but network security is broadly a subset of cyber security which, itself, is a subset of information security. While cyber security centers around how to protect the organization from different types of cyber attack, network security specifically focuses on defending against anything that may compromise the integrity of the corporate network.


Network security aims to protect data as it travels through the network between users and endpoints and normally involves protecting against DoS attacks, viruses, or worms, as well as preventing unauthorized access. This may also involve taking measures to prevent, say, social engineering attacks in which hackers aim to seize employees’ credentials – alongside other methods normally deployed to breach the network. Cyber security, meanwhile, protects the data living inside endpoints as well as corporate servers, and protects everything within the digital realm. As such, cyber security covers all the devices that an organization owns, and cyber security practitioners will normally aim to negate the threat from malware, phishing, SQL injection, and zero-day exploits, among other forms of attack.

网络安全旨在保护数据在用户和端点之间通过网络传输的数据,通常包括防止 DoS 攻击、病毒或蠕虫,以及防止未经授权的访问。这还可能涉及采取措施防止社会工程攻击,例如,黑客旨在获取员工凭据的社会工程攻击,以及通常用于破坏网络的其他方法。与此同时,网络安全可以保护存在于端点和企业服务器内部的数据,并保护数字领域内的一切。因此,网络安全涵盖组织拥有的所有设备,网络安全从业者通常旨在消除来自恶意软件、网络钓鱼、SQL 注入和零日漏洞以及其他形式攻击的威胁。

Why your business needs all three working in harmony


It feels as if the scale of cyber security threats is expanding, but what’s also clear is the variety of attack vectors and opportunities for hackers to strike is increasing. Having effective information security policies in place is crucial to this, with the volume of data expanding. But so too is adopting cyber security principles to stay abreast of the latest threats. Strong network security policies, meanwhile, ensure the organization’s corporate network is airtight, and all data transmitted across it is safe from exploitation.






