Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Security
Cyber Security

Security

← Back to Glossary
By NHI Mgmt Group Updated September 8, 2026 Domain: Cyber Security

Security is the set of controls used to protect information, systems, and assets from unauthorized access, misuse, disruption, or loss. It is primarily concerned with confidentiality, integrity, and availability. In an organisation, security is judged by how effectively it reduces risk and supports operational resilience within defined legal and business constraints.

Expanded Definition

Security in a cyber context is the disciplined use of preventive, detective, and corrective controls to reduce unauthorised access, misuse, disruption, and loss. It is not a single product or team function. It is an outcome that depends on policy, technical safeguards, monitoring, response, and accountability working together.

Practitioners often use security as an umbrella term, but the boundaries matter. A resilience plan may keep services running after failure, while security aims to stop or limit harmful events in the first place. Likewise, privacy, safety, and compliance overlap with security but are not identical. In guidance terms, the industry consensus is stable on the core CIA model, but different organisations weight confidentiality, integrity, and availability differently depending on their sector and threat profile.

For identity-heavy environments, security also extends to the trust relationships that allow people, workloads, services, and agents to act. That is why machine secrets, service accounts, and delegated access are part of the security surface, not a separate issue. For readers looking at machine identity governance, the OWASP Non-Human Identity Top 10 is a useful companion reference.

Examples and Use Cases

  • A bank restricts who can view payment records, which supports confidentiality and reduces insider misuse.
  • A software team validates every production change before release, helping preserve integrity and detect unauthorised modification.
  • An incident response function isolates a compromised endpoint, limiting spread and restoring availability after malicious activity.
  • A cloud team monitors service accounts and API keys, because exposed credentials can become a direct route to data access or abuse.
  • An organisation applies layered controls across network, endpoint, identity, and logging tooling, rather than relying on one control domain alone.

One practical tradeoff is that stronger control often increases friction. Tightening authentication, approval, and logging can slow users or automation, so security teams usually need to balance protection against operational speed. The common implementation reality is that weak identity hygiene often becomes the shortest path around otherwise strong perimeter controls.

Security Implications

When security is treated as a vague aspiration instead of a control discipline, organisations usually see uneven enforcement, blind spots, and delayed response. The result is not just higher breach likelihood. It is also larger blast radius when an access path, device, or dependency fails because no clear ownership or control boundary existed.

Misunderstanding security often leads to overreliance on a single layer, such as perimeter filtering or password policy, while ignoring monitoring, segmentation, recovery, and privileged access. That creates a false sense of coverage. In practice, the symptoms are familiar: excessive permissions, stale access, unreviewed exceptions, weak logging, and controls that exist on paper but are not operationally verified.

For machine identities and automation, the security consequence is especially sharp. A leaked token, embedded secret, or over-privileged service account can bypass human approval flows and act at machine speed. That means the failure is not only access compromise but also rapid lateral movement, data exposure, and difficult-to-detect misuse.

Domain and Governance Relevance

Security matters in every digital domain, but the governance questions change depending on what is being protected. In identity environments, the focus is less on a generic “secure system” statement and more on who owns access, how trust is established, how exceptions are approved, and how quickly misuse can be contained.

For NHI, the meaning becomes more operational. Security must cover non-human credentials, workload permissions, certificate lifecycles, and the delegation boundaries used by automation and AI agents. If those elements are not inventoried and governed, the organisation cannot reliably say which identities exist, what they can reach, or how they are revoked. That is why security and identity governance converge in modern environments.

In broader governance terms, security is the control layer that lets organisations use digital systems without losing control of them. Its practical value lies in making access decisions auditable, failures containable, and recovery plausible under legal, business, and operational constraints.

Risk and Threat Considerations

Security failures usually appear first as control gaps, then as exposure. The most material risks are unauthorised access, misuse of privilege, disruption of critical services, and loss of trust in data or automation. In identity-heavy environments, those risks scale quickly because one weak credential or trust relationship can affect many systems.

Failure mechanism: Attackers and abusive insiders typically exploit weak authentication, excessive privilege, poor segmentation, stale secrets, or missing monitoring to gain access and persist. Once inside, they can move laterally, alter data, exfiltrate information, or disrupt availability while blending into normal administrative activity.

Impact: The consequence is often wider than a single compromised account. Organisations can lose operational continuity, expose regulated data, invalidate audit evidence, and spend significant time re-establishing trust in systems, identities, and logs.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernSecurity is a governance outcome requiring policy, ownership, and risk decisions.
PR.AC-1 — Identity Management, Authentication, and Access ControlSecurity depends on limiting and validating access to systems and data.
DE.CM-1 — Security Continuous MonitoringSecurity requires ongoing visibility into misuse and control failure.
Recommendation — Establish governance roles and risk priorities so security controls stay aligned to business objectives. Enforce identity and access controls to prevent unauthorised use of protected resources. Monitor systems continuously to detect misuse, drift, and suspicious activity early.
CIS Controls v86 — Access Control ManagementSecurity depends on governing permissions and revoking unnecessary access.
8 — Audit Log ManagementSecurity needs logs that support detection, investigation, and accountability.
5 — Account ManagementSecurity is weakened when accounts, including service accounts, are stale or unowned.
Recommendation — Apply access control management to restrict privilege and reduce unauthorised access paths. Collect and protect audit logs so misuse and compromise can be investigated reliably. Manage accounts continuously to remove stale identities and prevent orphaned access.
OWASP Non-Human Identity Top 10NHI-01 — Inventory and OwnershipSecurity in NHI environments depends on knowing which non-human identities exist and who owns them.
NHI-03 — Secrets ManagementSecurity is directly affected by how machine credentials are stored and rotated.
NHI-07 — Monitoring and DetectionSecurity for automation requires visibility into abnormal NHI behaviour and misuse.
Recommendation — Inventory non-human identities and assign ownership so access can be governed and revoked. Protect, rotate, and scope secrets to limit credential abuse and downstream compromise. Monitor non-human identity activity to detect abuse, drift, and suspicious access patterns.

Practitioner Guidance

Why practitioners should care: Security is only useful when ownership is explicit. Practitioners should treat it as a measurable control outcome, not a slogan, because the same environment can look “secure” at the perimeter while remaining weak in identity, logging, or recovery.

Common misunderstanding: Teams often equate security with prevention alone. In reality, detection and containment matter just as much, especially where service accounts, automation, or delegated access can create fast-moving failure paths.

Practitioner takeaway: Define security by the controls you can verify, the identities you can account for, and the damage you can contain when a trust assumption fails.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org