Unit outline_

INFO5301: Information Security Management

Semester 2, 2026 [Normal evening] - Camperdown/Darlington, Sydney

This unit of study gives a broad view of the management aspects of information security. We emphasise corporate governance for information security, organisational structures within which information security is managed, risk assessment, and control structures. Planning for security, and regulatory issues, are also addressed.

Unit details and rules

Academic unit Computer Science
Credit points 6
Prerequisites
? 
None
Corequisites
? 
None
Prohibitions
? 
OINF5301
Assumed knowledge
? 

This unit of study assumes foundational knowledge of Information systems management. Two year IT industry exposure and a breadth of IT experience will be preferable

Available to study abroad and exchange students

Yes

Teaching staff

Coordinator Kanchana Thilakarathna, kanchana.thilakarathna@sydney.edu.au
The census date for this unit availability is 31 August 2026
Type Description Weight Due Length Use of AI
Written exam hurdle task Final exam
Supervised Final written exam
55% Formal exam period 2 hours AI prohibited
Outcomes assessed: LO2 LO3 LO4 LO5
Out-of-class quiz Assignment 1
Take-home assignment including short answer questions.
15% Week 06
Due date: 08 Sep 2026 at 23:59
2 weeks AI allowed
Outcomes assessed: LO1 LO2 LO3 LO4 LO5
Practical skill group assignment Assignment 2.1
This is the first part of the Group Project. This part involves in-depth understanding of a case study and in-class presentation of the case study.
10% Week 08
Due date: 23 Sep 2026 at 17:00
4 weeks AI allowed
Outcomes assessed: LO1 LO2 LO3 LO4 LO5
Practical skill group assignment Assignment 2.2
This is the second part of the Group project with group report and presentation. The project report contains individual contributions that will be counted to individual mark component of the group assignment.
20% Week 12
Due date: 27 Oct 2026 at 23:59
- AI allowed
Outcomes assessed: LO1 LO2 LO3 LO4 LO5
hurdle task = hurdle task ?
group assignment = group assignment ?

Assessment summary

Assignment 1: This is an individual assignment that quizzes the knowledge of each student in the topics of weeks 1-5 with questions similar to those on the final exam.
Assingment 2.1 & 2.2: In this practical group assignment, students are asked to analyse a case-study, develop information security management solution. The assessment includes an in-class pitch, written report and a presentation at the tutorial. The project report contains individual contributions that will be counted to individual mark component of the group assignment.
Final exam: Written exam that covers all aspects of the course. Obtaining at least 40% of the available marks from the written exam is a requirement to pass INFO5301.

Assessment criteria

The University awards common result grades, set out in the Coursework Policy 2014 (Schedule 1).

As a general guide, a high distinction indicates work of an exceptional standard, a distinction a very high standard, a credit a good standard, and a pass an acceptable standard.

Result name

Mark range

Description

High distinction

85 - 100

 

Distinction

75 - 84

 

Credit

65 - 74

 

Pass

50 - 64

 

Fail

0 - 49

It is a policy of the School of Computer Science that in order to pass this unit, a student must achieve at least 40% in the written examination. For subjects without a final exam, the 40% minimum requirement applies to the corresponding major assessment component specified by the lecturer. A student must also achieve an overall final mark of 50 or more. Any student not meeting these requirements may be given a maximum final mark of no more than 45 regardless of their average.

For more information see sydney.edu.au/students/guide-to-grades.

For more information see guide to grades.

Use of generative artificial intelligence (AI)

You can use generative AI tools for open assessments. Restrictions on AI use apply to secure, supervised assessments used to confirm if students have met specific learning outcomes.

Refer to the assessment table above to see if AI is allowed, for assessments in this unit and check Canvas for full instructions on assessment tasks and AI use.

If you use AI, you must always acknowledge it. Misusing AI may lead to a breach of the Academic Integrity Policy.

Visit the Current Students website for more information on AI in assessments, including details on how to acknowledge its use.

Late submission

In accordance with University policy, these penalties apply when written work is submitted after 11:59pm on the due date:

  • Deduction of 5% of the maximum mark for each calendar day after the due date.
  • After ten calendar days late, a mark of zero will be awarded.

This unit has an exception to the standard University policy or supplementary information has been provided by the unit coordinator. This information is displayed below:

For late submissions, a penalty of 5% of the maximum awardable marks will be taken per day (or part) late. If the assessment is submitted more than ten calendar days late, a mark of zero will be awarded.

Academic integrity

The University expects students to act ethically and honestly and will treat all allegations of academic integrity breaches seriously.

Our website provides information on academic integrity and the resources available to all students. This includes advice on how to avoid common breaches of academic integrity. Ensure that you have completed the Academic Honesty Education Module (AHEM) which is mandatory for all commencing coursework students

Penalties for serious breaches can significantly impact your studies and your career after graduation. It is important that you speak with your unit coordinator if you need help with completing assessments.

Visit the Current Students website for more information on AI in assessments, including details on how to acknowledge its use.

Simple extensions

If you encounter a problem submitting your work on time, you may be able to apply for an extension of five calendar days through a simple extension.  The application process will be different depending on the type of assessment and extensions cannot be granted for some assessment types like exams.

Special consideration

If exceptional circumstances mean you can’t complete an assessment, you need consideration for a longer period of time, or if you have essential commitments which impact your performance in an assessment, you may be eligible for special consideration or special arrangements.

Special consideration applications will not be affected by a simple extension application.

Using AI responsibly

Co-created with students, AI in Education includes lots of helpful examples of how students use generative AI tools to support their learning. It explains how generative AI works, the different tools available and how to use them responsibly and productively.

Support for students

The Support for Students Policy reflects the University’s commitment to supporting students in their academic journey and making the University safe for students. It is important that you read and understand this policy so that you are familiar with the range of support services available to you and understand how to engage with them.

The University uses email as its primary source of communication with students who need support under the Support for Students Policy. Make sure you check your University email regularly and respond to any communications received from the University.

Learning resources and detailed information about weekly assessment and learning activities can be accessed via Canvas. It is essential that you visit your unit of study Canvas site to ensure you are up to date with all of your tasks.

If you are having difficulties completing your studies, or are feeling unsure about your progress, we are here to help. You can access the support services offered by the University at any time:

Support and Services (including health and wellbeing services, financial support and learning support)
Course planning and administration
Meet with an Academic Adviser

WK Topic Learning activity Learning outcomes
Week 01 Introduction, nature and scope of Information Systems Security Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Information Security Risks and Challenges Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 02 Basic Principles of Information Security Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Basics Principles in Practice Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 03 Planning and designing for Information Security Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Case Studies: Cybersecurity Frameworks Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 04 Technical Aspects of Information Security Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Access Control Policies Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 05 Formal Aspects of Information Security Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Understanding Cybersecurity Best Practices Guidelines Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 06 Informal Aspects of Information Security Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Impact of Human Aspects Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 07 Information Security Standards and Regulations Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Understanding Regulations and Standards Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 08 Case studies: In class pitches from students Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Policy and regulation compliance Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 09 Information Security in Practice: Industry Guest Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Revision and assessment feedback Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 10 Risk Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Revision with questions Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 11 Impact of AI in Information Security Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
AI assisted Information Security Management Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 12 Emerging Trends in Information Security Management Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Assignment 2 Group Presentations Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5
Week 13 Unit review Lecture (2 hr) LO1 LO2 LO3 LO4 LO5
Exam preperation Tutorial (1 hr) LO1 LO2 LO3 LO4 LO5

Attendance and class requirements

- Tutorials complement the lectures by enabling students to apply and practice key concepts in the same week they are introduced.

- In-person attendance at both lectures and tutorials is highly encouraged.

- Attendance at tutorials will be recorded to monitor student engagement and most lectures starts with 0%-weighted Quiz to self-assess the understanding of the previous week.

- Week 3 and 9 tutorials include 0%-weighted submission to provide students with early feedback. 

- Week 8 lecture includes in-class presentations.

- Week 9 tutorial includes in-person feedback on Assignment 1.

- Week 10 tutorial covers early revision with exam preparation support.

 

Study commitment

Typically, there is a minimum expectation of 1.5-2 hours of student effort per week per credit point for units of study offered over a full semester. For a 6 credit point unit, this equates to roughly 120-150 hours of student effort in total.

Required readings

References are provided for guidance purposes only. Students are advised to consult these books in the university library. Purchase is not required.

- Information Security: Principles and Practices by Mark Merkow and James Breithaupt

- Computer Security: Art and Science by Bishop, Matt (Matthew A.); Sullivan, Elisabeth: Ruppel, Michelle 2019

- Principles of information systems security : text and cases by Gurpreet Dhillon

- Security in Computing by Charles Pfleeger and Shari Pfleeger

Learning outcomes are what students know, understand and are able to do on completion of a unit of study. They are aligned with the University's graduate qualities and are assessed as part of the curriculum.

At the completion of this unit, you should be able to:

  • LO1. Communicate on information security issues to both managers and technical staff
  • LO2. List and outline major concerns and issues of managing information security
  • LO3. Define, describe and discuss management and governance aspects of information security
  • LO4. Describe risk management methodology and control structures as applied to the management of information security
  • LO5. Describe and characterise the attributes of information security management practices.

Graduate qualities

The graduate qualities are the qualities and skills that all University of Sydney graduates must demonstrate on successful completion of an award course. As a future Sydney graduate, the set of qualities have been designed to equip you for the contemporary world.

GQ1 Depth of disciplinary expertise

Deep disciplinary expertise is the ability to integrate and rigorously apply knowledge, understanding and skills of a recognised discipline defined by scholarly activity, as well as familiarity with evolving practice of the discipline.

GQ2 Critical thinking and problem solving

Critical thinking and problem solving are the questioning of ideas, evidence and assumptions in order to propose and evaluate hypotheses or alternative arguments before formulating a conclusion or a solution to an identified problem.

GQ3 Oral and written communication

Effective communication, in both oral and written form, is the clear exchange of meaning in a manner that is appropriate to audience and context.

GQ4 Information and digital literacy

Information and digital literacy is the ability to locate, interpret, evaluate, manage, adapt, integrate, create and convey information using appropriate resources, tools and strategies.

GQ5 Inventiveness

Generating novel ideas and solutions.

GQ6 Cultural competence

Cultural Competence is the ability to actively, ethically, respectfully, and successfully engage across and between cultures. In the Australian context, this includes and celebrates Aboriginal and Torres Strait Islander cultures, knowledge systems, and a mature understanding of contemporary issues.

GQ7 Interdisciplinary effectiveness

Interdisciplinary effectiveness is the integration and synthesis of multiple viewpoints and practices, working effectively across disciplinary boundaries.

GQ8 Integrated professional, ethical, and personal identity

An integrated professional, ethical and personal identity is understanding the interaction between one’s personal and professional selves in an ethical context.

GQ9 Influence

Engaging others in a process, idea or vision.

Outcome map

Learning outcomes Graduate qualities
GQ1 GQ2 GQ3 GQ4 GQ5 GQ6 GQ7 GQ8 GQ9

This section outlines changes made to this unit following staff and student reviews.

The unit content has been refreshed to reflect current trends and industry best practices in information security management. Assessment structure and weighting have been revised to increase class engagement and understanding of real-world case-studies.

Disclaimer

Important: the University of Sydney regularly reviews units of study and reserves the right to change the units of study available annually. To stay up to date on available study options, including unit of study details and availability, refer to the relevant handbook.

To help you understand common terms that we use at the University, we offer an online glossary.