This document discusses key concepts in information security including definitions of security, common certifications, and the roles and responsibilities of a CISO. It defines information security as protecting information and systems from unauthorized access or harm. The CIA triad of confidentiality, integrity and availability is presented as a common framework. The CISO is described as the senior executive responsible for an organization's security vision and program. Several common security certifications are also listed such as CISSP, CISM, and Security+.