Information security means being able to protect data, which is at the heart of everything you do. There are several layers to information security. Information is at the deepest level, with application on top of that, then host, followed by network. All of these combined make up your critical assets. All of the traffic that is coming in from the Internet is going to enter your network. Your job is to prevent unauthorized outside sources from entering the network. It's important to have both your logical and physical infosec components operating at a high level to keep your network as secure as possible. From the network pieces, you have your host. Your host can be physical or virtual and is made up of your servers and operating system. On your host, you have your applications. Within the applications, you have the most important component to keep your data. Let's look at this system a little closer. Your network is made up of a variety of components, which can include your ethernet cables, routers, switches, gateways, firewalls, and more. The network is what allows edge devices, those that engage with your network, to come in. It also allows the devices within your network to get out. Edge devices include phones, tablets, laptops, desktops, and Internet of Things or IoT devices. Your host, which includes your OS, uses the network to allow traffic to get out. This can include traffic going to the Internet or going to the local access network or LAN. You will have applications running on your host. These applications vary widely from database servers to point of sale and customer relationship management systems. The application contains the data, the information we must secure. Information security uses both detective and preventative controls to protect data. Detective controls allow you to figure out if somebody has gained unauthorized access to your resources within your organization or if someone has attempted to gain access. Preventative controls do their best to prevent unauthorized actors from getting into your system in the first place. To aid in this, there are intrusion detection systems, or IDS, and intrusion prevention systems, or IPS. Using both detective and preventative methods helps improve your organization's network security.