INFORMATION SECURITY AND ASSURANCE
- Course
- MISY271 - INFORMATION SECURITY AND ASSURANCE
- Department
- Management Information Systems - English - Undergraduate
- Course Type
- Course
- Status
- Required
- Language
- English
- Credit
- 3
- ECTS
- 6
- T+P+L
- 3 + 0 + 0
- Course Coordinator(s)
- Asst. Prof. Dr. Sara SALEHI
- Prerequisite
Course Description
Information security is the state of being free from danger while Information Assurance (IA) is acting of managing risks and keeping information safe from harm. Both information security and information assurance encompasses computer security, communication security, operations security and physical security. The main objective of this course is to learn the fundamental concept of Information security models and practices that can help in planning, developing and performing security tasks. The course will address hardware, software, processes, communications, applications, policies and procedures with respect to organizational IT Security and Risk Management. Topics to be covered include Physical security, VPN, SSL, Cryptography, Digital Forensics, digital signature.
INFORMATION SECURITY AND ASSURANCE
Evaluation Tools (Active Term)
| Item | Type | Weight (%) |
|---|---|---|
| Midterm Exam | Midterm | 35 |
| Quiz | Quiz | 20 |
| Final Exam | Final | 45 |
| Total | 100 | |
Course outcomes
No course outcomes have been defined yet.
Course Syllabus
| Week | Topic |
|---|---|
| Week 1 | Introduction to Information security |
| Week 2 | Security needs, threats and attacks |
| Week 3 | Risk Management |
| Week 4 | Trending attacks |
| Week 5 | Attack prevention and mitigation Techniques |
| Week 6 | Access control, Biometrics, Watermarking |
| Week 7 | Midterm exam |
| Week 8 | Cryptography |
| Week 9 | SSL, Firewalls, VPN, |
| Week 10 | Security models and frameworks |
| Week 11 | Digital Forensics |
| Week 12 | Project presentation |
| Week 13 | Project presentation |
| Week 14 | Revision |
| Week 15 | Final Exam |
Reference Books & Course Materials
- 01 Principles of Information Security, 7th Edition by Micheal Whitman and Herbert Mattord
- 02 Security in Computing, 3rd Edition by Charles P. Pfleeger and Shari Lawrence Pfleeger
Learning Outcomes
- L01 To Identify and examine the foundational theory behind information security SOLO 3.5
- L02 To identify and assess the common threats faced by organizations SOLO 3.5
- L03 To design and develop the basic principle and technique to mitigate security issues SOLO 5
- L04 To examine the basic security principles and techniques when designing a system SOLO 3
- L05 To demonstrate how today's attacks and defenses work in practice SOLO 4
- L06 To evaluate the key concepts of information security and how they work SOLO 5
- L07 Apply the principles of cryptography, including encryption and hashing techniques, to protect digital information SOLO 4
- L08 Evaluate secure communication protocols, including Firewall, VPN and SSL, and demonstrate how they ensure data integrity and confidentiality SOLO 4.5
- L09 Analyze security models and frameworks to plan and develop effective information security strategies. SOLO 4.7
- L10 Examine the fundamentals of digital forensics and its role in identifying and resolving security breaches SOLO 3
Program Outcomes
- P01 Demonstrate comprehensive knowledge of key concepts across the breadth of effective application and use of MIS and innovative information technologies in organizations.
- P02 Demonstrate autonomy and responsibility in managing MIS projects and improving organizational processes
- P03 Demonstrate comprehensive understanding of appropriate enterprise frameworks, theories from the MIS to research and assess contemporary issues in the field and related allied fields and disciplines
- P04 Apply MIS knowledge to facilitate the acquisition, development, deployment, and management of information systems
- P05 Apply MIS knowledge to the exploitation of opportunities created by information technology innovations ensuring the alignment between MIS strategy and organizational strategy
- P06 Demonstrate ethical reasoning in relation to crucial MIS issues such as privacy, information security, and ethical use of information
- P07 Apply appropriate technologies and techniques to the collection and analysis of organizational and environmental data to facilitate evidence-based decision-making
- P08 Analyse organizational data to accurately identify organizational problems and propose solutions using MIS
- P09 Apply effective communication skills consistent with the professional environment
- P10 Apply effective collaboration skills consistent with the professional environment
Po-Lo Matrix
| LO | P01 | P02 | P03 | P04 | P05 | P06 | P07 | P08 | P09 | P10 | Average |
|---|---|---|---|---|---|---|---|---|---|---|---|
| L01 | 4 | 2 | 5 | 3 | 2 | 4 | 3 | 3 | 1 | 1 | 2.8 |
| L02 | 3 | 3 | 3 | 3 | 3 | 4 | 4 | 4 | 2 | 2 | 3.1 |
| L03 | 4 | 4 | 3 | 4 | 4 | 3 | 3 | 5 | 2 | 2 | 3.4 |
| L04 | 3 | 3 | 3 | 4 | 3 | 3 | 3 | 3 | 2 | 2 | 2.9 |
| L05 | 3 | 4 | 2 | 3 | 3 | 3 | 3 | 4 | 3 | 3 | 3.1 |
| L06 | 5 | 3 | 4 | 3 | 4 | 5 | 3 | 4 | 2 | 2 | 3.5 |
| L07 | 4 | 3 | 4 | 3 | 4 | 4 | 3 | 4 | 2 | 2 | 3.3 |
| L08 | 4 | 3 | 4 | 4 | 4 | 5 | 3 | 4 | 2 | 2 | 3.5 |
| L09 | 4 | 4 | 5 | 4 | 5 | 4 | 4 | 5 | 3 | 3 | 4.1 |
| L10 | 3 | 3 | 4 | 2 | 3 | 5 | 4 | 4 | 2 | 2 | 3.2 |