What is "integral security" (integrale Sicherheit), and where does information security sit within it?
It's the holistic view of all of an organisation's security domains at once — information security is only one slice of it.
* Integral security governs all protective domains as one wheel; information security (cool spokes) is just one group alongside physical-world security (warm spokes). *
Rather than managing each protective concern in its own silo, integral security looks at the whole organisation's risk picture together, so the gaps between silos don't get overlooked. The domains fall into two groups:
- Information security (the logical, data-and-process slice): information protection, logical (IT) security, data protection, contingency/emergency planning, insurance cover, and quality assurance.
- Further, "physical-world" security: physical security, personnel/personal protection, occupational safety, and environmental protection.
Why it matters: the strongest logical controls are worthless if someone can walk into the server room (physical security) or a fire destroys the site (environmental protection). An attacker — or an accident — takes whichever path is weakest, so these concerns have to be governed as one whole, not as disconnected departments.
Tip: Picture information security as one wedge of a wheel labelled "integral security"; the other wedges (physical, personnel, safety, environment) are just as load-bearing.
Go deeper:
Security convergence (Wikipedia) — the holistic-integration idea behind integrale Sicherheit — merging physical and information/IT security into one risk programme.