Security and information security are two
different things. Security is the process of reducing
risk or threats that can jeopardise an organisation
meanwhile information security is a business
requirement to protect the organisation’s
investment in its information assets [7]. Many
researchers and scholars have discussed the
definition of information security. The Information
Security Management System (ISMS) defines
information security as a preservation of
confidentiality, integrity, and availability of
information; in addition with other properties such
as authenticity, accountability, non-repudiation and
reliability [11]. The Committee on National
Security System (CNSS) defines information
security as the protection of information and its
critical elements. The elements include the systems
and hardware that are used to store and transmit the
information [12]. C.I.A. triangle, the paramount
model in information security, also called the
information security triad, is always highlighted
when the issues of information security are
discussed.