Home/Knowledge hub/What is information security?
GlossaryWhat is information security?
The set of measures to protect information against unauthorised access, loss and manipulation, including in your DMS.
In short
Information security is the set of technical, organizational, and procedural measures to protect information from unauthorized access, loss, manipulation, and unwanted dissemination, regardless of whether that information is digital or physical.
On this page
What is information security?
Information security is broader than cybersecurity. It is not just about firewalls and antivirus software, but also about who has access to which documents, how long they are retained, who can modify them, and how you can demonstrate that during an audit.it.
In M-Files, information security is structurally built-in. Access rights are managed at the document level based on metadata, not through folder structures that anyone with the right disk access can bypass. All actions are logged in an immutable audit trail.
SoftAdvice designs your information security architecture as part of every M-Files implementation. From information classification and access rights schemes to retention policies and user training, security is not an afterthought but a core component of your information architecture..
Information security in M-Files
Document-level access control
Every document has exact rights per user, role or process step.
Encryption
Documents stored and transmitted encrypted. Data unreadable without authorisation.
GDPR compliance
Technical and organisational measures demonstrably implemented. Ready for a DPA audit.
Audit trail
Every access and change recorded. Immediately visible who did what.
Automatic retention policy
Documents with personal data automatically deleted after the retention period.
Smaller attack surface
Centralisation replaces scattered files. Fewer copies, fewer risks.
Addressing information security structurally
- Step 1
Information classification
Categorise documents by sensitivity: public, internal, confidential, strictly confidential.
- Step 2
Design access rights
Define who has access per category based on role, department and process step.
- Step 3
Technical measures
Encryption, multi-factor authentication and automatic timeouts configured.
- Step 4
Awareness and training
Technical measures fail without human compliance. SoftAdvice guides your team.
- Step 5
Periodic review
Information security is an ongoing process. Quarterly reviews keep your setup current.
Frequently Asked Questions
What is information security?
Information security is the set of measures, technical, organizational, and procedural, to protect information against unauthorized access, loss, manipulation, and dissemination.
What is the difference with cybersecurity?
Cybersecurity focuses on protection against digital attacks. Information security is broader: it also includes paper documents, access control in buildings, procedures, and human behavior.
How does M-Files contribute to information security?
M-Files offers document-level access rights, encrypted storage, complete audit trails, automatic retention policies, and integration with Microsoft authentication. This makes information security structural rather than ad hoc.
What is ISO 27001?
ISO 27001 is the international standard for information security. It describes requirements for an Information Security Management System (ISMS). An M-Files implementation with audit trail and access control directly contributes to ISO 27001 compliance.
Is information security only for large companies?
No. SMEs are an increasingly popular target for cybercriminals. M-Files makes enterprise-level information security accessible to organizations of all sizes.
Our consultants are happy to think along with you.
Plan a conversationAddress information security structurally?
Discover how M-Files combines access control, audit trail and encryption in one platform.
Continue learning
Related terms, articles and the M-Files capabilities behind this topic.