My SMTP server installed with ISPCONFIG allows for anyone to send from it it seems, is there a way to secure it so that it only allows mailer accounts on the machine to send, and also possibly required a username/password like POP3 requires?
Yes it is possible. If you installed using the perfect setup you should already have this enabled. Otherwise check out saslauthd as this is the mechanism used in the perfect setup. For Ubuntu it is the 5th page of the tutorial.
Please make sure that you have this line in your postfix main.cf: To check if your server is really a open relay, you may use this test: http://www.abuse.net/relay.html