> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/company-operating-manual/security-compliance-and-data/information-assurance.md).

# Information Assurance

### Purpose

Information assurance ensures that information risks are understood and managed.

### Assurance Areas

Information assurance covers:

* confidentiality
* integrity
* availability
* data protection
* access control
* auditability
* resilience
* supplier assurance
* incident response

### Assurance Activities

Projects may require:

* security requirements review
* data protection review
* threat modelling
* vulnerability scanning
* penetration testing
* supplier security review
* operational readiness review
* risk acceptance
