Skip to content
Back to BlogWriting Tips

INFO5301: why do technical students underperform in this unit?

10 min read1,903 wordsNEW

Information Security Management sits inside an engineering faculty and is taught to students who mostly arrive with technical backgrounds, which makes its central demand easy to miss. The unit is not asking how an attack works.

Information Security Management sits inside an engineering faculty and is taught to students who mostly arrive with technical backgrounds, which makes its central demand easy to miss. The unit is not asking how an attack works. It is asking how an organisation decides what to protect, who is accountable when it fails, and how you explain that decision to a board that will never read a packet capture. Students who answer technically on a governance question lose marks while feeling they answered well. Below is how MAAS mentors reframe the unit for Vietnamese students at the University of Sydney.

Author: MAAS Editorial Team · Reviewed by a Senior Information Systems mentor (PhD, Information Security Governance)
Last updated: 2026-08-10
Category: writing-tips


What is INFO5301 and who is it for?

Direct answer: INFO5301 Information Security Management is a 6-credit-point postgraduate unit at the University of Sydney, taught within the Faculty of Engineering in computer science, and offered in both Semester 1 and Semester 2 as an evening unit at Camperdown and Darlington. It has no formal prerequisites, but assumes foundational knowledge of information systems management, and the unit page notes that around two years of IT industry exposure is preferable.

Evidence: These details come from the university's own unit of study page, which records credit points, session availability, assumed knowledge and learning outcomes. The evening scheduling is a signal worth reading: the unit is built to be accessible to people already working, and its questions are framed the way they arise in workplaces rather than in labs.

Example: A student with a strong development background chose the unit expecting applied security work and spent the first fortnight waiting for the technical content to begin. It had begun. He had classified governance frameworks as preamble because they did not look like the security material he knew.

The phrase "assumed knowledge" also does real work here. It is not a prerequisite the university enforces, so nobody will stop you enrolling without it, and nobody will slow down for you either.


What is actually being assessed?

Direct answer: Your ability to reason about security as an organisational problem and to communicate that reasoning to two very different audiences. The unit's published outcomes are explicit about it: communicating on information security issues to both managers and technical staff, identifying the major concerns in managing information security, discussing management and governance aspects, describing risk management methodology and control structures, and characterising the attributes of information security management practices.

Evidence: Read that first outcome closely, because it is unusual. Most units assess whether you understand something. This one assesses whether you can move an understanding between audiences with different vocabularies and different stakes. That is a communication outcome sitting in a technical degree, and it is examinable.

Example: Asked to advise on a control decision, one answer explained the cryptographic mechanism in accurate detail and never mentioned cost, disruption to staff, or who would own the residual risk. It was correct and unusable. The rewrite kept two sentences of mechanism and spent the rest on what the organisation would be accepting by choosing it.


Where does the technical instinct actively cost marks?

Direct answer: In four recurring places, all of them cases where a technically correct answer sits at the wrong altitude for the question.

The question is about The instinctive answer The answer the unit rewards
Risk assessment Listing vulnerabilities found Estimating likelihood and impact, then ranking so that limited budget goes somewhere defensible
Controls The strongest available control The proportionate control, justified against the risk it addresses and its cost to the business
Governance Who administers the system Who is accountable, who decides, and what evidence the board sees that the decision is working
An incident The root cause in the stack The failure in the control structure that let a known risk go unmanaged

Evidence: This altitude problem is why the field settled on structured management systems rather than technical checklists. The ISO/IEC 27001 family frames security as a management system with defined responsibilities and continual review, and risk management guidance such as ISO 31000 treats risk as something an organisation decides how much of to accept, not something to be eliminated. The NIST Cybersecurity Framework is organised around functions that an organisation performs rather than technologies it installs, for the same reason. Where a question invokes any of these, it is asking about structure and accountability.

Example: A student wrote that an organisation "should implement multi-factor authentication across all systems." Asked what it would cost, which systems could not support it, and what would happen to the help desk in week one, he narrowed the recommendation to the systems holding regulated data, with a stated timeline for the rest. The security position was slightly weaker on paper and the recommendation became one a manager could act on.


How do you handle regulation without turning the answer into a summary?

Direct answer: Use the regulation to constrain a decision rather than to fill a section. A paragraph describing what a law requires is background. An argument about how the requirement changes what the organisation should do is analysis.

Evidence: Security planning and regulatory issues are named in the unit description, and regulation matters here precisely because it converts a business judgement into an obligation. Australian organisations covered by the Privacy Act operate under a mandatory notifiable data breaches scheme, which changes the calculus around detection: an organisation that cannot tell whether data was accessed has a compliance problem on top of a security one. That is the kind of consequence worth writing about.

Example: One draft devoted a page to summarising privacy obligations and then recommended controls that had no connection to them. Cutting the summary to a short paragraph and using the notification duty to justify investment in logging and detection produced a shorter section that actually carried the argument.


Where do international students most often lose marks?

Direct answer: In writing that stays descriptive under a question that asks for a judgement, and in hedging that has no boundary. Both are more visible in a management unit than in a technical one, because the marker is assessing your reasoning rather than checking your output against a correct answer.

Evidence: The outcome about communicating to managers and technical staff means register is assessed, not merely tolerated. Writing to a manager means leading with the decision and its consequence; writing to technical staff means the mechanism and its limits. A submission that mixes the two registers indiscriminately has not demonstrated the outcome even if every sentence in it is true.

Example: A recommendation opened with three paragraphs of context before reaching its point. The content was sound and the structure worked against it, because an executive-facing recommendation that buries the recommendation has failed at the thing it was demonstrating. Moving the decision to the first sentence and pushing the reasoning underneath changed nothing factual and changed the reading experience entirely.

A note on terminology: keep the English terms exact. Risk appetite, residual risk, control, and threat have precise and non-interchangeable meanings in this field, and a translated approximation collapses distinctions the marking depends on.


How should you prepare across the semester?

Direct answer: Build a working vocabulary of frameworks early, then practise applying them to organisations rather than describing them. The failure mode is knowing three frameworks well in the abstract and being unable to say which one a given situation calls for.

A pattern that works: in the first weeks, write your own one-paragraph account of what each major framework is for and what it does not cover, since knowing the limits is what lets you choose between them. From the midpoint, take real breach cases reported in the press and write a short analysis of the governance failure rather than the technical one. Before assessments, practise the two registers deliberately by writing the same recommendation twice, once for a board and once for an engineering lead.

Evidence: Assessment structure varies between offerings and the authoritative version is the unit outline published shortly before teaching begins, so confirm yours rather than relying on a previous year. Archived handbook entries for this unit have shown a split between in-semester assessment and a final examination, with the examination carrying the larger share, which is worth planning for even if your offering differs.


What do MAAS mentors actually do on this unit?

MAAS works as an academic advisor. The most useful early intervention here is checking altitude: you bring a draft answer, and a mentor asks whether it addresses the organisational question or the technical one underneath it. From there the work is ordinary, meaning a structural read against the learning outcomes, a check on whether your claims are supported at the strength you have stated them, and attention to whether your recommendations are written for the audience the task names. You write and submit your own work, and referencing is checked inside that read.


Frequently asked questions

Is INFO5301 a technical unit?
It sits in the Faculty of Engineering but its outcomes are management and governance outcomes. Expect to reason about risk, accountability and communication rather than to build or break systems.

What are the prerequisites?
The unit page lists none. It does state assumed knowledge of information systems management and notes that roughly two years of IT industry exposure is preferable, which is guidance rather than an enforced barrier.

How many credit points is it, and when does it run?
Six credit points, offered in both Semester 1 and Semester 2 as an evening unit at Camperdown and Darlington.

Do I need work experience to cope?
It helps, because the unit's questions are workplace-shaped. Without it, compensate by reading published breach investigations and regulator reports, which supply the organisational context that experience would otherwise give you.

How is it assessed?
Your unit outline is the authority and is published shortly before teaching begins. Historically the unit has combined in-semester assessment with a final examination weighted more heavily, so prepare for timed conditions as well as written work.

Should I cite standards or academic literature?
Both, in different roles. Standards such as the ISO/IEC 27001 family define what good practice claims to be; peer-reviewed research tells you where it succeeds and fails in practice. Citing only the first produces a compliant-sounding answer with no critical content.


Talk to a MAAS mentor about your unit


References

International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection: Information security management systems: Requirements. ISO.

International Organization for Standardization. (2018). ISO 31000:2018 Risk management: Guidelines. ISO.

National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). U.S. Department of Commerce. https://doi.org/10.6028/NIST.CSWP.29

Whitman, M. E., & Mattord, H. J. (2021). Management of information security (6th ed.). Cengage Learning.

Soomro, Z. A., Shah, M. H., & Ahmed, J. (2016). Information security management needs more holistic approach: A literature review. International Journal of Information Management, 36(2), 215–225. https://doi.org/10.1016/j.ijinfomgt.2015.11.009

Share this articleFacebookLinkedInZaloEmail
Want guidance like this?

From this article
to your dissertation.

A 15-minute discovery call: our PhD & Master experts translate this framework into your specific topic and supervisor expectations.