INFO 1016 Security Foundations
INFO 1016 Overview
- Adelaide University
- Semester 2, 2026
- an undergraduate cybersecurity course
- a security foundations course
INFO 1016 spans CIA security properties, threat landscapes, network layers, cryptography, social engineering, attack frameworks, vulnerabilities, Essential Eight controls and incident recovery. It is taught within Adelaide University. It is an undergraduate cybersecurity course.
- Security protects properties Controls should be tied to confidentiality, integrity or availability of a named asset.
- Trust boundaries locate risk A system becomes analysable when authority and data crossing points are explicit.
- Defence needs layers Preventive controls can fail, so detection, response and recovery remain necessary.
- Frameworks organise evidence A framework structures inquiry; it does not prove every listed control is effective.
How INFO 1016 is assessed
| Component | Weight | Format |
|---|---|---|
| Case Study | 30% | the landed official record |
| Peer Review | 40% | the landed official record |
| Creative Work | 30% | the landed official record |
The official page publishes Case Study 30%, Peer Review 40% and Creative Work 30% at the landed official record; the separately captured current route is byte-identical and not counted as a second source.
What INFO 1016 covers
The sequence opens at Security Objectives, Assets and Trade-offs, develops its central analytical shift in Human Threats and Social Engineering, and closes with Defence, Incident Response and Recovery.
Security Objectives, Assets and Trade-offs
confidentiality · integrity · availability · prioritise security properties for a named system and consequence02Threat Landscapes and Incident Evidence
threat actor · attack surface · indicator · connect current threat evidence to assets, exposure and plausible actor action03Networks, Addressing and Secure Web Communication
IP routing · DNS · HTTPS · follow a connection through link, addressing, naming, routing and secure application layers04Cryptography, Encryption and Hashing
encryption · symmetric cryptography · cryptographic hash · select cryptographic functions based on confidentiality, integrity and key needs05Human Threats and Social Engineering
social engineering · insider threat · security awareness · analyse how authority, urgency and workflow enable manipulation06Attack Chains and Adversary Behaviour
Cyber Kill Chain · MITRE ATT&CK · data exfiltration · trace observed and possible adversary actions into detection and interruption opportunities07Vulnerabilities, CVE, CWE and CVSS
vulnerability · CVE · CVSS · combine technical severity with exposure, exploitability, asset value and compensating controls08Defence, Incident Response and Recovery
Essential Eight · incident response · backup · combine baseline controls with evidence-preserving response and tested recoveryIt carries credit value controlled by the live study plan. It is positioned as a security foundations course.
The course moves from assets and threats through both human and technical attack paths to defence, response and recovery.
The retrieved current-offering evidence does not publish a complete assessment weighting for info1016.
a case study, peer review and creative work; official category weights are pinned
The operational assessment conditions matter here.
The captured official page does not list a separate final examination.
What makes info1016 demanding is concrete: reasoning across people, protocols and controls without confusing one successful defence with elimination of residual risk
No component hurdle is asserted beyond the captured official assessment list.
For enrolment planning, Consult the current Adelaide enrolment controls.
The sequence opens at Security Objectives, Assets and Trade-offs, develops its central analytical shift in Human Threats and Social Engineering, and closes with Defence, Incident Response and Recovery.
Respond to credential theft
- 1Contain the account and preserve evidence.
- 1Identify assets, sessions and affected identities.
- 1Trace entry, actions and possible exfiltration.
- 1Recover, notify and improve layered controls.
Key terms
- confidentiality
- Protection against unauthorised disclosure. This chapter uses the concept when students prioritise security properties for a named system and consequence.
- integrity
- Protection of accuracy, completeness and authorised change. It helps explain the reasoning required to prioritise security properties for a named system and consequence.
- availability
- Reliable authorised access when needed. Its limit matters because maximum protection of one property can reduce another property or legitimate use.
- threat actor
- Person or group with capability and intent to cause harm. This chapter uses the concept when students connect current threat evidence to assets, exposure and plausible actor action.
- attack surface
- Exposed points through which a system may be influenced. It helps explain the reasoning required to connect current threat evidence to assets, exposure and plausible actor action.
- indicator
- Observable sign potentially associated with malicious activity. Its limit matters because a dramatic incident elsewhere does not establish likelihood for this system.
- IP routing
- Forwarding packets among networks using addresses and routes. This chapter uses the concept when students follow a connection through link, addressing, naming, routing and secure application layers.
- DNS
- System resolving names to resource information. It helps explain the reasoning required to follow a connection through link, addressing, naming, routing and secure application layers.
- HTTPS
- HTTP protected by transport encryption and authentication mechanisms. Its limit matters because a padlock does not establish that the endpoint is trustworthy in every other respect.
- encryption
- Reversible transformation protecting data with a key. This chapter uses the concept when students select cryptographic functions based on confidentiality, integrity and key needs.
- symmetric cryptography
- Encryption using a shared secret key. It helps explain the reasoning required to select cryptographic functions based on confidentiality, integrity and key needs.
- cryptographic hash
- One-way digest designed to reveal changes and resist manipulation. Its limit matters because algorithm names alone do not solve key generation, storage, rotation or endpoint compromise.
- social engineering
- Manipulation of people to bypass or misuse controls. This chapter uses the concept when students analyse how authority, urgency and workflow enable manipulation.
- insider threat
- Risk arising from trusted access used maliciously, negligently or under coercion. It helps explain the reasoning required to analyse how authority, urgency and workflow enable manipulation.
INFO 1016 FAQ
How does assessment work in Security Foundations?
A case study, peer review and creative work; official category weights are pinned. The captured official page does not list a separate final examination. No component hurdle is asserted beyond the captured official assessment list.
Where is the hardest reasoning in Security Foundations?
Reasoning across people, protocols and controls without confusing one successful defence with elimination of residual risk. INFO 1016 spans CIA security properties, threat landscapes, network layers, cryptography, social engineering, attack frameworks, vulnerabilities, Essential Eight controls and incident recovery.
Which pass conditions apply in Security Foundations?
No component hurdle is asserted beyond the captured official assessment list. A case study, peer review and creative work; official category weights are pinned. The captured official page does not list a separate final examination.
Which teaching period does this Security Foundations resource cover?
It is aligned to Semester 2, 2026; confirm your enrolled class and timetable in the current institutional system. INFO 1016 spans CIA security properties, threat landscapes, network layers, cryptography, social engineering, attack frameworks, vulnerabilities, Essential Eight controls and incident recovery.
What should a student check before enrolling in Security Foundations?
Consult the current Adelaide enrolment controls. This resource covers Semester 2, 2026. INFO 1016 spans CIA security properties, threat landscapes, network layers, cryptography, social engineering, attack frameworks, vulnerabilities, Essential Eight controls and incident recovery.
Who controls the official rules for Security Foundations?
The university does. This is an independent info1016 study resource; current institutional instructions remain authoritative for assessment operation. INFO 1016 spans CIA security properties, threat landscapes, network layers, cryptography, social engineering, attack frameworks, vulnerabilities, Essential Eight controls and incident recovery.
What form does the final assessed task take in Security Foundations?
The captured official page does not list a separate final examination. A case study, peer review and creative work; official category weights are pinned. No component hurdle is asserted beyond the captured official assessment list.
How to prepare for the assessments
Retrieve the course map, practise the recurring method—identify the asset, security property, actor and trust boundary, trace the attack path through human and technical layers, map preventive, detective and corrective controls, test control failure and residual risk, then plan accountable response and recovery—on changed scenarios, and verify every operational assessment detail in the live institutional system.
Your AI Cybersecurity tutor for INFO 1016
Stuck on a hard INFO 1016 question? Sia is AskSia’s AI Cybersecurity tutor — ask any INFO 1016 Security Foundations question and get a clear, step-by-step explanation grounded in how the course is actually taught and assessed. Read this whole study guide free, then take your hardest questions to Sia.