ArticleslgStudy

science

Information security management

Information security management is a science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand Information security management rather than just read about it. In short: Information security management (ISM) defines and manages controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. The core of ISM includes information risk management, a process that involves the assessment of the risks an organization must deal with in the management and protection of asset…

Key takeaways

  • Information security management belongs to science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect Information security management to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of Information security management from memory before moving on to harder problems.

Reference excerpt

Information security management (ISM) defines and manages controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. The core of ISM includes information risk management, a process that involves the assessment of the risks an organization must deal with in the management and protection of assets, as well as the dissemination of the risks to all appropriate stakeholders. This requires proper asset identification and valuation steps, including evaluating the value of confidentiality, integrity, availability, and replacement of assets. As part of information security management, an organization may implement an information security management system and other best practices found in the ISO/IEC 27001, ISO/IEC 27002, and ISO/IEC 27035 standards on information security. Information security management has become an increasingly important part of modern organizations as it helps secure large databases often found within large organizations. These databases often store sensitive information, such as personal identifiers and financial records. A breach in these databases can ruin a company's reputation or put millions of people's information at risk. For this reason, information security management is often discussed alongside cybersecurity practices, many of which are directly correlated or directly used in Information Security Management Systems (ISMS).

Risk management and mitigation Managing information security in essence means managing and mitigating the various threats and vulnerabilities to assets, while at the same time balancing the management effort expended on potential threats and vulnerabilities by gauging the probability of them actually occurring. These ideas can be summarized into the Protection Motivation Theory, or PMT. The PMT "seeks to explain why individuals adopt or engage in protective behavior." There are two main mechanisms of the PMT: threat appraisals and coping appraisals. Threat appraisals refer to how people perceive the severity of a threat and their vulnerability to a threat. A meteorite crashing into a server room is certainly a threat, for example, but an information security officer will likely put little effort into preparing for such a threat. Just as people don't have to start preparing for the end of the world just because of the existence of a global seed bank. The second half of the PMT is coping appraisals. This refers to self-efficacy and response efficacy. Self-efficacy is someone's perceived confidence in their ability to complete a task. Response efficacy refers to someone's belief in a protective action's effectiveness. Coping appraisals also include response costs, or any possible expenditures potentially required of someone to follow through with a protective action, such as money, time, or effort. In order for the PMT to be successful, a person must have a strong sense of self-efficacy and response efficacy with the task at hand, along with a low perception of reward costs (which can also be influenced by self-efficacy). After appropriate asset identification and valuation have occurred, risk management and mitigation of risks to those assets involves the analysis of the following issues:

Threats: Unwanted events that could cause the deliberate or accidental loss, damage, or misuse of information assets. Vulnerabilities: How susceptible information assets and associated controls are to exploitation by one or more threats. This can also be referred to as threat appraisals in the PMT. Impact and likelihood: The magnitude of potential damage to information assets from threats and vulnerabilities and how serious of a risk they pose to the assets; cost–benefit analysis may also be part of the impact assessment or separate from it. Mitigation: The proposed method(s) for minimizing the impact and likelihood of potential threats and vulnerabilities. This is directly linked to coping appraisal strength when it comes to implementing each method. Once a threat and/or vulnerability has been identified and assessed as having a high threat appraisal on information assets, a mitigation plan can be enacted. The mitigation method is chosen largely depends on which of the seven information technology (IT) domains the threat and/or vulnerability resides in. The threat of user apathy toward security policies (the user domain) will require a much different mitigation plan than the one used to limit the threat of unauthorized probing and scanning of a network (the LAN-to-WAN domain). Some of the most common reasons organizations may struggle implementing risk management protocol are:

Social engineering tactics tricking workers into giving out personal information, especially if they lack important online safety tools A lack of understanding in personal role or responsibility in information security management, or a complete disregard for it A lack of education in information security management In order for a mitigation strategy to be effective, both the technological and user side of the strategy must be functioning with minimal errors.

… excerpt ends here. Continue reading the full article.

Worked examples

Example 1 — a first encounter with Information security management

Start with the simplest possible case. Write down what Information security management claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to Information security management before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about Information security management ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of Information security management

In research
Information security management appears in science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses Information security management in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
Information security management is common in secondary-school and first-year university syllabi. It links to neighbouring topics Information management, Information technology management, Security, so understanding it makes those chapters shorter.
In everyday life
Look for Information security management outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “Information security management” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study Information security management in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what Information security management means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain Information security management out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is Information security management in simple terms?

Information security management (ISM) defines and manages controls that an organization needs to implement to ensure that it is sensibly protecting the confidentiality, availability, and integrity of assets from threats and vulnerabilities. The core of ISM includes information risk management, a pr…

Why does Information security management matter?

Because it connects several science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study Information security management?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on Information security management.

Tags

  • Information management
  • Information technology management
  • Security

Keep exploring