← Back to courses

Information Security Management: Module 1

Information Security Fundamentals

Learn why information security management means and why it is needed by industries and organisations.

Estimated reading time

8 minutes

What is information security?

Information security focuses on the protection of information and the technology that stores or transfers them.

Information security is essential because information has certain characteristics that provide value, and if one of them is violated, the information is no longer useful. The three characteristics that make information valuable are confidentiality, integrity and availability.

Why is information security management needed?

Nowadays, there are many problems involving information security.

One such example is the collapse of the Australian hedge fund Levitas Capital. According to the ACS Information Age article, the scam started with a spoofed Zoom invitation. After accessing the link, a hedge fund manager unknowingly installed malware and lost access to his email account. Then, attackers transferred about $8.7 million to several different accounts. While the hedge fund manager was able to stop the transfers, it was too late. After the cyberattack, Levitas Capital is no longer in operation.

Another example is the cyberattack that happened to Queensland University of Technology (QUT) in late 2022. One day, attackers targeted the university's internal storage drive, exposing current and former staff and student's personal details. The attack also involved the campus printers printing out ransomware notes several times, which asked for a "modest royalty" to keep the data under wraps (Darwen, 2024).

A more recent example is the Canvas breach that happened during May 2026. Canvas is a Learning Management System (LMS) managed by Instructure. On May 1, Steve Proud, the Chief Information Security Officer of Instructure, said that Canvas "recently experienced a cybersecurity incident perpetrated by a criminal threat actor." On May 6, he said that the company finished their investigation and did not find any suspicious activity.

However, according to a ZDNet article that reported the incident, students later discovered login issues. One day later, Canvas' login interface was vandalised with ransom notes posted by the instigators of the ongoing attack, asking Instructure to contact the attacker group. The group also stole personal information from about 275 million students from roughly 9,000 schools from all around the world. While access to the site is restored, this has left a devastating impact on Instructure's reputation.

Based on these incidents, usage of ransomware to threaten victims is the new normal. These cyberattacks could happen to any company in any industry, which is why information security is more necessary that it was before.

Security goals

According to Rhodes, the traditional definition of information security includes three fundamental goals.

These are

  • Confidentiality,
  • Integrity, and
  • Availability.

These three can be remembered by the abbreviation "CIA".

Confidentiality refers to the limiting of access to the information to only those who need or use it, and preventing access to those who do not. Integrity refers to the completeness and wholeness of data. When data is altered, corrupted or damaged during entry, storage or transmission, it loses its integrity. Availability describes how accessible data is to those who need it. The data must also be in readable format.

Note that confidentiality and privacy are different terms. Privacy is the end goal of information security while confidentiality is the means to attain security.

Additional security goals

According to Rhodes, these additional goals could also be considered necessary to establish security.

  • Identification
  • Authentication
  • Authorisation
  • Accountability
  • Non-repudiation

Identification refers to the system's ability to recognise users and who has rightful access to the information. Authentication verifies the user's identity. Authorisation specifies what the user is allowed to do with the data. Accountability is when a system or control keeps track of activity done to the data. Each activity should also be traced back to the person who did the activity. Non-repudiation refers to creating irrefutable proof that the activity occurred and the user has done it.

Security controls

According to Rhodes, controls refer to the measures taken to counter security threats, reduce vulnerabilities or prevent attacks.

There are three kinds of controls:

  • Preventive
  • Detective
  • Corrective

Preventive controls reduce the occurrence of incidents, detective controls identify incidents or incoming attacks, while corrective controls correct or restore the data or files that were corrupted during an attack or incident.

Sources

Tonkin, C. (2020). Dodgy Zoom invite brings down $75m hedge fund. ACS Information Age.
Tassell, D. (2022). Queensland University of Technology dealing with cybersecurity attack. 7NEWS.
Osborne, C. (2026). Worried about the nationwide Canvas data breach? Take these 6 steps now. Instructure.
Proud, S. (2026). Confirmed Security Incident. ZDNet.
Rhodes, A. (2023). IFN541 Information Security Management: Why we need Information Security Management. [Presentation]. Canvas.
Rhodes, A. (2023). IFN541 Information Security Management: Fundamental Information Security Concepts. [Presentation]. Canvas.
Previous Next