9.3. Information security management

Information security management is the practice of protecting information needed by the organisation to conduct its business.

Its purpose is to ensure that information is appropriately protected in accordance with its importance and sensitivity.

Information security management supports confidentiality, integrity, and availability of information.

The practice should balance the need for security with the need for usability and access.

Information security risks should be identified, assessed, and treated.

Information security management applies to all services and practices.


2. How This Applies to TakeCars (Car Rental Marketplace)

This practice is quietly critical for marketplaces, because trust collapses instantly when information is mishandled.

a) What “information” means at TakeCars

Information is not just passwords or servers. It includes:

  • Customer identity details
  • Driver licence data
  • Payment and transaction data
  • Booking history
  • Host contact details
  • Dispute and incident records

Loss or misuse of any of these directly damages trust and creates legal exposure.


b) Confidentiality, integrity, availability (CIA) in TakeCars terms

Confidentiality

  • Customer data is not exposed to other renters
  • Hosts only see information required for the booking
  • Support access is role-based

Failure example:

  • Sending booking details to the wrong host

Integrity

  • Booking details are accurate and not altered incorrectly
  • Payment amounts and dates are correct
  • Dispute records reflect what actually happened

Failure example:

  • Manual edits causing incorrect charges or dates

Availability

  • Customers and hosts can access bookings when needed
  • Support can retrieve records during disputes
  • Platform access during peak travel periods

Failure example:

  • System outage during holiday pickups

c) Balancing security and usability (very ITIL-specific)

Too much security:

  • Overly complex verification
  • Excessive manual checks
  • Friction that blocks bookings

Too little security:

  • Fraud
  • Data leaks
  • Regulatory violations

ITIL explicitly requires balance, not maximum lockdown.


d) Exam-critical insight

If the exam asks:

“What is the purpose of information security management?”

Correct logic:

  • Protect information
  • Based on importance and sensitivity
  • Support confidentiality, integrity, and availability
  • Apply across all services

Answers focused only on technology are incomplete.


3. Key Things to Read / Remember Right Before the Exam

Information security management (high probability)

  • A practice
  • Protects organisational information
  • Based on CIA:
    • Confidentiality
    • Integrity
    • Availability
  • Balances security and usability

Common exam traps

  • Information security is only an IT responsibility → False
  • Maximum security is always best → False
  • Information security applies only to data storage → False

One-line memory hook

Information security protects confidentiality, integrity, and availability while remaining usable.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *