{"id":83046,"date":"2026-09-25T15:31:36","date_gmt":"2026-09-25T18:31:36","guid":{"rendered":"https:\/\/a3aengenharia.com\/?post_type=articles&#038;p=83046"},"modified":"2026-09-25T15:31:36","modified_gmt":"2026-09-25T18:31:36","slug":"information-security-pillars-risks-good-practices","status":"publish","type":"articles","link":"https:\/\/a3aengenharia.com\/en-us\/content\/technical-articles\/information-security-pillars-risks-good-practices\/","title":{"rendered":"Information Security: What It Is, Pillars, Risks, and Good Practices"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Information security is one of the central topics of modern digital life.<\/p>\n<p class=\"wp-block-paragraph\">Companies, professionals, and individuals increasingly depend on data, systems, networks, cloud services, connected devices, cameras, access control, corporate applications, and digital platforms.<\/p>\n<p class=\"wp-block-paragraph\">The greater this dependence, the greater the need to protect information against unauthorized access, loss, alteration, exposure, or unavailability.<\/p>\n<p class=\"wp-block-paragraph\">That is why understanding information security is not only a concern for IT professionals. It is a necessity for any organization that depends on data to operate, serve customers, make decisions, and maintain trust.<\/p>\n<p class=\"wp-block-paragraph\">In this article, we explain the pillars of information security, its main risks, its relationship with LGPD and data protection, security culture, information-security policy, and good practices for connected environments.<\/p>\n<h2 id=\"h-o-que-e-seguranca-da-informacao\" class=\"wp-block-heading\">What is information security?<\/h2>\n<p class=\"wp-block-paragraph\">Information security is the set of practices, processes, policies, technologies, and controls used to protect information.<\/p>\n<p class=\"wp-block-paragraph\">This information may exist in digital systems, physical documents, emails, databases, images, access logs, contracts, projects, reports, mobile devices, servers, cloud services, or corporate platforms.<\/p>\n<p class=\"wp-block-paragraph\">The objective is to reduce risks related to unauthorized access, unauthorized modification, loss, data leakage, unavailability, and improper use of information.<\/p>\n<p class=\"wp-block-paragraph\">In practice, information security is not limited to installing tools. It involves people, processes, governance, infrastructure, and organizational culture.<\/p>\n<p class=\"wp-block-paragraph\">A company may have good systems and still remain vulnerable if access is poorly managed, data is shared without criteria, or there is no clear procedure for sensitive decisions.<\/p>\n\n<h2 id=\"h-os-tres-pilares-confidencialidade-integridade-e-disponibilidade\" class=\"wp-block-heading\">The three pillars: confidentiality, integrity, and availability<\/h2>\n<p class=\"wp-block-paragraph\">Information security is commonly explained through three pillars: confidentiality, integrity, and availability.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Confidentiality<\/strong> means ensuring that information is accessed only by authorized people, systems, or processes.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Integrity<\/strong> means preserving information as correct, complete, and reliable, preventing improper changes or loss of accuracy.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Availability<\/strong> means ensuring that information is accessible when needed.<\/p>\n<p class=\"wp-block-paragraph\">These three pillars help explain different types of risk.<\/p>\n<p class=\"wp-block-paragraph\">A data breach compromises confidentiality. An improper change to a record compromises integrity. A failure that prevents access to a critical system compromises availability.<\/p>\n<p class=\"wp-block-paragraph\">In real environments, these pillars are interconnected. An access problem may affect operations, trust, compliance, and business continuity.<\/p>\n<h2 id=\"h-seguranca-da-informacao-nao-e-apenas-seguranca-digital\" class=\"wp-block-heading\">Information security is not only digital security<\/h2>\n<p class=\"wp-block-paragraph\">Digital security is an important part of information security, but it is not the whole concept.<\/p>\n<p class=\"wp-block-paragraph\">Digital security focuses mainly on protecting systems, networks, devices, applications, credentials, and online environments.<\/p>\n<p class=\"wp-block-paragraph\">Information security is broader. It also covers documents, processes, people, physical files, contracts, images, records, internal policies, and organizational decisions.<\/p>\n<p class=\"wp-block-paragraph\">Data may leak because of a technical failure, but it may also be exposed through improper printing, sending to the wrong recipient, informal conversation, improper disposal, excessive permissions, or lack of procedure.<\/p>\n<p class=\"wp-block-paragraph\">For this reason, information security needs to be treated as management, not merely as technology.<\/p>\n\n<h2 id=\"h-principais-riscos-para-informacoes-e-dados\" class=\"wp-block-heading\">Main risks to information and data<\/h2>\n<p class=\"wp-block-paragraph\">Information-security risks can appear in many forms.<\/p>\n<p class=\"wp-block-paragraph\">Some are technical. Others are human, procedural, or organizational.<\/p>\n<p class=\"wp-block-paragraph\">Common risks include:<\/p>\n<ul class=\"wp-block-list\"><li>leakage of personal or corporate data;<\/li><li>weak or reused passwords;<\/li><li>phishing and social engineering;<\/li><li>excessive permissions;<\/li><li>lack of access control;<\/li><li>backup failures;<\/li><li>outdated devices;<\/li><li>improper file sharing;<\/li><li>absence of an information-security policy;<\/li><li>improper use of cloud services;<\/li><li>lack of organized incident response;<\/li><li>poor integration between physical and digital security.<\/li><\/ul>\n<p class=\"wp-block-paragraph\">The central point is that information must be protected throughout its lifecycle: collection, use, storage, sharing, retention, and disposal.<\/p>\n\n<h2 id=\"h-lgpd-e-protecao-de-dados-qual-e-a-relacao\" class=\"wp-block-heading\">LGPD and data protection: what is the relationship?<\/h2>\n<p class=\"wp-block-paragraph\">Brazil&#8217;s LGPD increased attention to the processing of personal data.<\/p>\n<p class=\"wp-block-paragraph\">It does not replace information security, but it reinforces the need for controls, procedures, and accountability in the use of personal data.<\/p>\n<p class=\"wp-block-paragraph\">Data such as name, CPF, phone number, email, address, image, biometrics, access records, and financial information need to be processed with purpose, necessity, security, and transparency.<\/p>\n<p class=\"wp-block-paragraph\">This means data protection is not only a legal obligation. It is also a technical and organizational practice.<\/p>\n<p class=\"wp-block-paragraph\">Companies need to know which data they collect, why they collect it, who accesses it, where it is stored, how long it is retained, and how it is protected.<\/p>\n<p class=\"wp-block-paragraph\">In environments involving images, biometrics, and facial recognition, this care is even more important. For further reading, see <a href=\"\/conteudo\/artigos-tecnicos\/biometria-reconhecimento-facial-riscos-lgpd-boas-praticas\/\">Biometrics and Facial Recognition: risks, LGPD, and good practices<\/a>.<\/p>\n\n<h2 id=\"h-politica-de-seguranca-da-informacao-por-que-ela-e-necessaria\" class=\"wp-block-heading\">Information-security policy: why is it necessary?<\/h2>\n<p class=\"wp-block-paragraph\">An information-security policy guides how an organization should protect its data, systems, access, devices, and processes.<\/p>\n<p class=\"wp-block-paragraph\">It should turn security principles into understandable rules for daily operations.<\/p>\n<p class=\"wp-block-paragraph\">A good policy may address topics such as:<\/p>\n<ul class=\"wp-block-list\"><li>creation and removal of users;<\/li><li>password use and two-factor authentication;<\/li><li>permission control;<\/li><li>use of corporate and personal devices;<\/li><li>remote access;<\/li><li>file sharing;<\/li><li>email use;<\/li><li>processing of personal data;<\/li><li>incident response;<\/li><li>supplier contracting;<\/li><li>information storage and disposal.<\/li><\/ul>\n<p class=\"wp-block-paragraph\">But the policy cannot be merely a formal document.<\/p>\n<p class=\"wp-block-paragraph\">It needs to be communicated, trained, reviewed, and applied. Otherwise, it becomes a file that exists but does not guide decisions.<\/p>\n\n<h2 id=\"h-cultura-de-seguranca-quando-regras-viram-comportamento\" class=\"wp-block-heading\">Security culture: when rules become behavior<\/h2>\n<p class=\"wp-block-paragraph\">Security culture is what takes security out of the document and into everyday routine.<\/p>\n<p class=\"wp-block-paragraph\">It appears when people know how to identify risks, know the correct channels, understand which information requires care, and feel authorized to verify before acting.<\/p>\n<p class=\"wp-block-paragraph\">A mature security culture does not automatically blame the user. It creates conditions that make safe decisions easier.<\/p>\n<p class=\"wp-block-paragraph\">This involves clear communication, training, leadership, simple processes, practical examples, and recurring reinforcement.<\/p>\n<p class=\"wp-block-paragraph\">In companies, security culture reduces risks related to phishing, social engineering, data leakage, improper sharing, and informal approvals.<\/p>\n<p class=\"wp-block-paragraph\">For further reading on this point in the corporate environment, see <a href=\"\/conteudo\/artigos-tecnicos\/engenharia-social-no-ambiente-corporativo\/\">Social Engineering in the corporate environment<\/a>.<\/p>\n<h2 id=\"h-phishing-engenharia-social-e-o-fator-humano\" class=\"wp-block-heading\">Phishing, social engineering, and the human factor<\/h2>\n<p class=\"wp-block-paragraph\">Many incidents begin with a human decision: clicking a link, opening an attachment, sharing a code, granting access, or responding to a fake request.<\/p>\n<p class=\"wp-block-paragraph\">That is why phishing and social engineering are important topics within information security.<\/p>\n<p class=\"wp-block-paragraph\">Phishing tries to deceive users into providing data, credentials, or unsafe actions. Social engineering exploits trust, urgency, authority, and lack of verification.<\/p>\n<p class=\"wp-block-paragraph\">These risks should not be treated merely as individual failures. They also reveal weaknesses in processes, training, and culture.<\/p>\n<p class=\"wp-block-paragraph\">For a practical explanation of phishing, see <a href=\"\/conteudo\/artigos-tecnicos\/phishing-o-que-e-como-identificar\/\">Phishing: what it is, how to identify it, and why it still works<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Also see the content on <a href=\"\/conteudo\/artigos-tecnicos\/poder-da-engenharia-social-phishing-seguranca-informacao\/\">social engineering, digital risks, phishing, and information security<\/a>.<\/p>\n\n<h2 id=\"h-controle-de-acesso-quem-pode-acessar-o-que\" class=\"wp-block-heading\">Access control: who can access what?<\/h2>\n<p class=\"wp-block-paragraph\">Access control is one of the most important elements of information security.<\/p>\n<p class=\"wp-block-paragraph\">It defines who can access a given dataset, system, physical environment, or technical resource.<\/p>\n<p class=\"wp-block-paragraph\">The basic principle is simple: each person should have only the access necessary to perform their role.<\/p>\n<p class=\"wp-block-paragraph\">In practice, this requires:<\/p>\n<ul class=\"wp-block-list\"><li>definition of access profiles;<\/li><li>formal approval for sensitive permissions;<\/li><li>periodic review of users;<\/li><li>rapid removal of unnecessary access;<\/li><li>control of third parties and suppliers;<\/li><li>logging of critical access;<\/li><li>integration between physical and digital access.<\/li><\/ul>\n<p class=\"wp-block-paragraph\">Access control also connects to electronic security. Badges, biometrics, entry control, cameras, and digital systems need to be designed in an integrated way.<\/p>\n<p class=\"wp-block-paragraph\">To understand risks in this convergence, see <a href=\"\/conteudo\/artigos-tecnicos\/como-evitar-sistemas-seguranca-fisica-porta-entrada-ataques\/\">how to prevent physical-security systems from becoming entry points for cyberattacks<\/a>.<\/p>\n\n<h2 id=\"h-gestao-de-riscos-de-seguranca-da-informacao\" class=\"wp-block-heading\">Information-security risk management<\/h2>\n<p class=\"wp-block-paragraph\">Risk management helps prioritize what should be protected first.<\/p>\n<p class=\"wp-block-paragraph\">Not all information has the same level of sensitivity. Not every system has the same operational impact.<\/p>\n<p class=\"wp-block-paragraph\">An organization needs to identify assets, critical data, essential systems, sensitive access, technical dependencies, and processes that cannot stop.<\/p>\n<p class=\"wp-block-paragraph\">It should then assess threats, vulnerabilities, probability, impact, and existing controls.<\/p>\n<p class=\"wp-block-paragraph\">Some questions help:<\/p>\n<ul class=\"wp-block-list\"><li>which data is most sensitive?<\/li><li>which systems are critical?<\/li><li>who has access to important information?<\/li><li>how is that access approved?<\/li><li>is there a reliable backup?<\/li><li>is there an incident plan?<\/li><li>is physical security integrated with networks and cloud?<\/li><\/ul>\n<p class=\"wp-block-paragraph\">Risk management does not eliminate every problem, but it helps organizations make more rational and proportionate decisions.<\/p>\n\n<h2 id=\"h-seguranca-da-informacao-em-cloud-redes-e-sistemas-conectados\" class=\"wp-block-heading\">Information security in cloud, networks, and connected systems<\/h2>\n<p class=\"wp-block-paragraph\">Information security also depends on the infrastructure that supports digital services.<\/p>\n<p class=\"wp-block-paragraph\">Poorly organized networks, outdated devices, uncontrolled remote access, poorly configured cloud services, and undocumented connected systems can increase risk.<\/p>\n<p class=\"wp-block-paragraph\">Cloud computing, for example, may provide advanced capabilities, but it requires configuration, access control, permission management, backup, and governance.<\/p>\n<p class=\"wp-block-paragraph\">To understand the infrastructure behind these services, see <a href=\"\/conteudo\/artigos-tecnicos\/computacao-em-nuvem-na-pratica-como-funciona\/\">Cloud computing in practice<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Networks also play an essential role. Instability, poor segmentation, bottlenecks, or lack of control can affect performance and security. For further reading, see <a href=\"\/conteudo\/artigos-tecnicos\/tipos-de-redes-de-computadores\/\">Types of Computer Networks<\/a> and <a href=\"\/conteudo\/artigos-tecnicos\/desempenho-em-redes-de-computadores\/\">Computer Network Performance<\/a>.<\/p>\n<h2 id=\"h-governanca-de-seguranca-da-informacao\" class=\"wp-block-heading\">Information-security governance<\/h2>\n<p class=\"wp-block-paragraph\">Information-security governance defines responsibilities, criteria, and monitoring mechanisms.<\/p>\n<p class=\"wp-block-paragraph\">Without governance, important decisions become scattered: who approves access, who responds to incidents, who reviews permissions, who updates policies, who assesses suppliers, and who monitors risk.<\/p>\n<p class=\"wp-block-paragraph\">Good governance organizes roles, processes, indicators, audits, reviews, and accountability.<\/p>\n<p class=\"wp-block-paragraph\">References such as ISO 27001 help structure information-security management systems, but maturity depends on practical application within the organization&#8217;s context.<\/p>\n<p class=\"wp-block-paragraph\">Governance is not bureaucracy when it helps reduce improvisation and makes decisions more verifiable.<\/p>\n\n<h2 id=\"h-boas-praticas-para-fortalecer-a-seguranca-da-informacao\" class=\"wp-block-heading\">Good practices for strengthening information security<\/h2>\n<p class=\"wp-block-paragraph\">Some good practices help strengthen information security in different types of organizations:<\/p>\n<ul class=\"wp-block-list\"><li>map data, systems, and critical assets;<\/li><li>define an information-security policy;<\/li><li>create access-control criteria;<\/li><li>use two-factor authentication;<\/li><li>review permissions periodically;<\/li><li>train teams against phishing and social engineering;<\/li><li>maintain tested backups;<\/li><li>document critical processes;<\/li><li>define an incident-response plan;<\/li><li>protect personal data in accordance with LGPD;<\/li><li>assess suppliers and third parties;<\/li><li>keep networks, systems, and devices updated;<\/li><li>integrate physical and digital security;<\/li><li>perform periodic audits and assessments.<\/li><\/ul>\n<p class=\"wp-block-paragraph\">Security improves when it stops being a one-off action and becomes part of the management cycle.<\/p>\n\n<h2 id=\"h-o-papel-da-engenharia-em-ambientes-mais-seguros\" class=\"wp-block-heading\">The role of engineering in safer environments<\/h2>\n<p class=\"wp-block-paragraph\">Information security does not depend only on software.<\/p>\n<p class=\"wp-block-paragraph\">It also depends on infrastructure, power, networks, access control, cameras, servers, cloud systems, documentation, commissioning, and maintenance.<\/p>\n<p class=\"wp-block-paragraph\">In connected environments, engineering helps turn controls into verifiable solutions.<\/p>\n<p class=\"wp-block-paragraph\">This means designing correctly, integrating systems, testing deliveries, documenting configurations, reviewing access, assessing risks, and keeping infrastructure operating reliably.<\/p>\n<p class=\"wp-block-paragraph\">When physical security, digital security, and operations work together, the organization reduces risk and improves its ability to respond to incidents.<\/p>\n<p class=\"wp-block-paragraph\">Ultimately, information security is a combination of technology, processes, people, and engineering.<\/p>\n<div class=\"bloco-apoio-artigo\"><p><strong>Where A3A Engenharia fits in<\/strong><\/p><p>A3A Engenharia works with projects, assessments, audits, networks, electronic security, infrastructure, commissioning, maintenance engineering, project management, and technical consulting.<\/p><p>In connected environments, protecting information depends on well-designed systems, controlled access, defined processes, and reliable infrastructure.<\/p><\/div>\n<div class=\"bloco-apoio-artigo\"><p><strong>Related technical content<\/strong><\/p><ul><li><a href=\"\/conteudo\/artigos-tecnicos\/phishing-o-que-e-como-identificar\/\">Phishing: what it is, how to identify it, and why it still works<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/poder-da-engenharia-social-phishing-seguranca-informacao\/\">The power of social engineering: digital risks, phishing, and information security<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/engenharia-social-no-ambiente-corporativo\/\">Social Engineering in the corporate environment<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/golpes-digitais-protecao-de-dados-como-se-proteger\/\">Digital scams and data protection<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/computacao-em-nuvem-na-pratica-como-funciona\/\">Cloud computing in practice<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/biometria-reconhecimento-facial-riscos-lgpd-boas-praticas\/\">Biometrics and Facial Recognition: risks, LGPD, and good practices<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/como-evitar-sistemas-seguranca-fisica-porta-entrada-ataques\/\">How to prevent physical-security systems from becoming entry points for cyberattacks<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/tipos-de-redes-de-computadores\/\">Types of Computer Networks<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/desempenho-em-redes-de-computadores\/\">Computer Network Performance<\/a><\/li><\/ul><\/div>\n<div class=\"bloco-apoio-artigo\"><p><strong>Related services<\/strong><\/p><ul><li><a href=\"\/servicos\/planejamento\/consultoria-tecnica\/\">Technical Consulting<\/a><\/li><li><a href=\"\/servicos\/levantamento-e-diagnostico\/auditoria-tecnica\/\">Technical Audit<\/a><\/li><li><a href=\"\/servicos\/planejamento\/projeto-de-sistema-integrado-de-seguranca-eletronica\/\">Integrated Electronic Security System Design<\/a><\/li><li><a href=\"\/servicos\/implementacao\/comissionamento\/\">Commissioning<\/a><\/li><li><a href=\"\/servicos\/operacao\/engenharia-de-manutencao\/\">Maintenance Engineering<\/a><\/li><li><a href=\"\/servicos\/implementacao\/gestao-de-projetos\/\">Project Management<\/a><\/li><li><a href=\"\/servicos\/servicos-complementares\/emissao-de-pareceres-tecnicos\/\">Technical Opinions<\/a><\/li><\/ul><\/div>\n<div class=\"bloco-apoio-artigo\"><p><strong>Technical references<\/strong><\/p><ul><li>ISO\/IEC 27001 \u2014 Information security.<\/li><li>ISO\/IEC 27002 \u2014 Information security controls.<\/li><li>NIST Cybersecurity Framework.<\/li><li>CIS Controls \u2014 cybersecurity good practices.<\/li><li>LGPD \u2014 Brazilian General Data Protection Law.<\/li><\/ul><\/div>\n<div class=\"bloco-apoio-artigo\"><p><strong>Recommended supplementary materials<\/strong><\/p><ul><li><a href=\"\/conteudo\/artigos-tecnicos\/phishing-o-que-e-como-identificar\/\">Phishing and identification of digital scams<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/engenharia-social-no-ambiente-corporativo\/\">Security culture in the corporate environment<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/golpes-digitais-protecao-de-dados-como-se-proteger\/\">Digital scams and data protection<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/computacao-em-nuvem-na-pratica-como-funciona\/\">Cloud computing in practice<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/biometria-reconhecimento-facial-riscos-lgpd-boas-praticas\/\">Biometrics, facial recognition, and LGPD<\/a><\/li><li><a href=\"\/conteudo\/artigos-tecnicos\/como-evitar-sistemas-seguranca-fisica-porta-entrada-ataques\/\">Physical security and cyberattacks<\/a><\/li><\/ul><\/div>\n<div class=\"bloco-apoio-artigo faq-artigo\"><p><strong>FAQ<\/strong><\/p><p><strong>1. What is information security?<\/strong><br>Information security is the set of practices, policies, processes, and technologies used to protect information against unauthorized access, modification, loss, leakage, or unavailability.<\/p><p><strong>2. What are the pillars of information security?<\/strong><br>The main pillars are confidentiality, integrity, and availability.<\/p><p><strong>3. What is the difference between digital security and information security?<\/strong><br>Digital security focuses on systems, networks, and devices. Information security is broader and includes data, documents, processes, people, policies, and governance.<\/p><p><strong>4. How does LGPD relate to information security?<\/strong><br>LGPD requires care in the processing of personal data, which depends on access controls, data protection, policies, processes, and information security.<\/p><p><strong>5. What is an information-security policy?<\/strong><br>It is a document that defines rules and responsibilities for protecting data, systems, access, devices, and processes within an organization.<\/p><p><strong>6. Why is security culture important?<\/strong><br>Because rules only work when they become behavior. Security culture helps people recognize risks and make safer decisions.<\/p><p><strong>7. How can companies improve information security?<\/strong><br>By mapping data and assets, controlling access, training teams, maintaining backups, creating policies, reviewing permissions, protecting personal data, and carrying out audits.<\/p><\/div>\n<div class=\"conclusao-artigo\"><p><strong>Conclusion<\/strong><\/p><p>Information security is essential for protecting data, systems, processes, and operations in an increasingly connected environment.<\/p><p>It depends on confidentiality, integrity, and availability, but also on culture, policy, governance, access control, and risk management.<\/p><p>More than a set of tools, information security is an ongoing practice involving people, processes, technology, and engineering.<\/p><p>Organizations that address the subject in an integrated manner reduce risks, protect data, and make safer decisions.<\/p><\/div>\n<div class=\"cta-final-artigo\"><p><strong>Does your company treat information security as a strategy?<\/strong><\/p><p>Data, networks, access, systems, and infrastructure need to work together to reduce risk and protect operations.<\/p><p><a href=\"\/contato\/\"><strong>Talk to an A3A Engenharia specialist<\/strong><\/a>.<\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>Understand what information security is, its pillars, main risks, relationship with LGPD, and good practices for protecting data, systems, and operations.<\/p>\n","protected":false},"author":1,"featured_media":78627,"parent":0,"template":"","meta":{"_a3a_global_related_solutions":[],"_a3a_global_related_services":[],"_a3a_global_related_materials":[],"_a3a_post_lang":"en-us","_a3a_translation_group_id":"519dd678-bb91-4b5a-a6f9-a0f49bbf8db3","_a3a_i18n_canonical_slug":"information-security-pillars-risks-good-practices","_a3a_prod_post_id":"","_a3a_lang_url_en-us":"","_a3a_lang_url_es-es":""},"categories":[],"segments":[],"mercados":[],"etapas":[],"class_list":["post-83046","articles","type-articles","status-publish","has-post-thumbnail","hentry"],"_links":{"self":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/83046","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles"}],"about":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/types\/articles"}],"author":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/83046\/revisions"}],"predecessor-version":[{"id":83052,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/83046\/revisions\/83052"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media\/78627"}],"wp:attachment":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media?parent=83046"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/categories?post=83046"},{"taxonomy":"segments","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/segments?post=83046"},{"taxonomy":"mercados","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/mercados?post=83046"},{"taxonomy":"etapas","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/etapas?post=83046"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}