Information security management is the practice of protecting information needed by the organisation to conduct its business.
Its purpose is to ensure that information is appropriately protected in accordance with its importance and sensitivity.
Information security management supports confidentiality, integrity, and availability of information.
The practice should balance the need for security with the need for usability and access.
Information security risks should be identified, assessed, and treated.
Information security management applies to all services and practices.
2. How This Applies to TakeCars (Car Rental Marketplace)
This practice is quietly critical for marketplaces, because trust collapses instantly when information is mishandled.
a) What “information” means at TakeCars
Information is not just passwords or servers. It includes:
- Customer identity details
- Driver licence data
- Payment and transaction data
- Booking history
- Host contact details
- Dispute and incident records
Loss or misuse of any of these directly damages trust and creates legal exposure.
b) Confidentiality, integrity, availability (CIA) in TakeCars terms
Confidentiality
- Customer data is not exposed to other renters
- Hosts only see information required for the booking
- Support access is role-based
Failure example:
- Sending booking details to the wrong host
Integrity
- Booking details are accurate and not altered incorrectly
- Payment amounts and dates are correct
- Dispute records reflect what actually happened
Failure example:
- Manual edits causing incorrect charges or dates
Availability
- Customers and hosts can access bookings when needed
- Support can retrieve records during disputes
- Platform access during peak travel periods
Failure example:
- System outage during holiday pickups
c) Balancing security and usability (very ITIL-specific)
Too much security:
- Overly complex verification
- Excessive manual checks
- Friction that blocks bookings
Too little security:
- Fraud
- Data leaks
- Regulatory violations
ITIL explicitly requires balance, not maximum lockdown.
d) Exam-critical insight
If the exam asks:
“What is the purpose of information security management?”
Correct logic:
- Protect information
- Based on importance and sensitivity
- Support confidentiality, integrity, and availability
- Apply across all services
Answers focused only on technology are incomplete.
3. Key Things to Read / Remember Right Before the Exam
Information security management (high probability)
- A practice
- Protects organisational information
- Based on CIA:
- Confidentiality
- Integrity
- Availability
- Balances security and usability
Common exam traps
- Information security is only an IT responsibility → False
- Maximum security is always best → False
- Information security applies only to data storage → False
One-line memory hook
Information security protects confidentiality, integrity, and availability while remaining usable.
Leave a Reply