CSCI 4607

Information Risk Management

Credit Hours
3
Contact Hours
4
Course Coordinator
Ghaith Husari
Cross-listed
CSCI 5607 — Information Risk Management

Catalog Description

Explores industry standards and best practices used to assess organizational information security compliance, determine organizational information security maturity, and guide cybersecurity policy development and implementation.

Prerequisite(s)

None

Course Outcomes

  • Enumerate an organization’s information assets and classify the risks associated with unauthorized use (information disclosure, modification, and/or deletion) of each resource. ( Student Outcome CY1 )
  • Compare and contrast common threats to enterprise information security, including the attack vectors they exploit (physical, electronic, and/or procedural), the resources they threaten, and the nature, likelihood, and relative severity of each threat.
  • Apply the key features of major contemporary security standards, including formal standards like the NIST Cybersecurity framework, the ISO 27000 series standards, PCI DSS, and COBIT. ( Student Outcome CY1 )
  • Identify and assess the relative severity of likely threats to a given organization’s information asset using both (1) formal security standards and (2) industry conventions such as the SANS Top 20 Threats and the FAIR (Factor Analysis of Information Risk) Framework.
  • Develop policies for managing key risks to information assets, including ones for (1) preventing attacks; (2) reducing the potential damage from information compromise; (3) identifying and responding to attacks in progress; and (4) recovering from attacks.

Topics

  • Current state of security and the Internet
  • Common threats to enterprise information security
  • Inventorying and enterprise’s information assets
  • Contemporary standards for information security
  • Security audits: common concerns, critical controls
  • Security policy development
  • The politics of security policy implementation, including recordkeeping (i.e., logging)
  • Recent topics in computer security

No syllabi uploaded yet.