Relate course work to the current job responsibilities
School of Computer and Information Sciences
COURSE SYLLABUS
Course Information
ISOL533 - M51 Info Security & Risk Mgmt
Fall 2020 Full Term
Course Format: Hybrid
CRN: 11719
Class Time and Location: F 08:00 AM - 10:00 PM, DAL
Residency Session: 10/09/2020 - 10/11/2020
Instructor Information
Name: Olatunji Arowolo
Email: [email protected]
Phone: 817-821-4486
Office Location: Virtual
Office Hours/Preferred Contact Times: By Appointment only
Course Description
The course provides a methodology to identify an institution�s information technology
assets, the proper way to determine the necessary level of protection required, and
techniques for developing budgets for security implementations. Credit, 3 hrs.
Course Objectives
Upon completion of this course:
Describe the components of an effective organizational risk management
program.
Describe the process of performing risk assessments.
Identify assets and activities to protect within an organization.
Explain the basic concepts of and need for risk management.
Learner Outcomes
Outcome 2.3: Students examine risk management strategies for protecting
assets.
Course Website
Access to the course website is required via the iLearn portal on the University of the
Cumberlands website: http://www.ucumberlands.edu/ilearn/
or https://ucumberlands.blackboard.com/
Required Books and Resources
Title: Managing Risk in Information Systems
Subtitle: **PLEASE SEE BOOKSTORE LINK BELOW TO PURCHASE
REQUIRED MATERIALS
Authors: Darril Gibson
Publisher: Jones & Bartlett Publishers
Publication Date: 2014-07-01
Course Required text can be found and purchased via the UC Barnes and Noble
Bookstore: https://cumber.bncollege.com/shop/cumberlands/page/find-textbooks
Requirements and Policies
Academic Integrity/Plagiarism
At a Christian liberal arts university committed to the pursuit of truth and
understanding, any act of academic dishonesty is especially distressing and cannot be
tolerated. In general, academic dishonesty involves the abuse and misuse of
information or people to gain an undeserved academic advantage or evaluation. The
common forms of academic dishonesty include:
Cheating – using deception in the taking of tests or the preparation of written
work, using unauthorized materials, copying another person’s work with or without
consent, or assisting another in such activities.
Week Topic & Reading Assignments
1
Introduction to Course
Chapter 1: Risk Management
Fundamentals Lab #1: Identifying
Threats and Vulnerabilities in an IT
Infrastructure
Welcome Discussion
Quiz / Homework
Assignment
*Failing to Participate in
Week 1 may result in being
dropped from the course.
2
Chapter 3: Managing Compliance
Lab #2: Aligning Risks, Threats,
and Vulnerabilities to COBIT P09
Quiz / Homework
Assignment
3
Chapter 2: Managing Risk: Threats,
Vulnerabilities, and Exploits
Quiz / Homework
Assignment
Discussion
4
Chapter 4: Developing a Risk
Management Plan Lab #3: Defining
Scope & Structure for an IT Risk
Management Plan
Quiz / Homework
Assignment
5
Chapter 5: Defining Risk
Assessment Approaches Chapter 6:
Performing a Risk Assessment Lab
#4: Performing a Qualitative Risk
Assessment
Quiz / Homework
Assignment
6
Required Residency Session Group Research Paper
Presentation &
Practical Connection
Assignment
7
Chapter 7: Identifying Assets and
Activities to be Protected Lab #5:
Identifying Risks, Threats,
Vulnerabilities using Zenmap® GUI
(Nmap) and Nessus® Reports
Quiz / Homework
Assignment
8
Chapter 8: Identifying/Analyzing
Threats, Weaknesses, and Exploits
Midterm Exam
9
Chapter 9: Identifying/Analyzing
Risk Mitigation Security Controls
Quiz / Homework
Assignment
10
Chapter 10: Planning Risk
Mitigation Throughout Your
Organization
Quiz / Homework
Assignment
11
Chapter 11: Turning Risk
Assessment into a Risk Mitigation
Plan Lab #6: Developing a Risk-
Mitigation Plan Outline
Quiz / Homework
Assignment
12
Chapter 12: Mitigating Risk with a
Business Impact Analysis Lab #7:
Performing a Business Impact
Analysis
Quiz / Homework
Assignment
13
Chapter 13: Mitigating Risk with a
Business Continuity Plan Lab #8:
Performing a Business Continuity
Plan
Quiz / Homework
Assignment
Discussion
14
Chapter 14: Mitigating Risk with a
Disaster Recovery Plan Lab #9:
Developing Disaster Recovery
Procedures & Recovery Instructions
Quiz / Homework
Assignment
15
Chapter 15: Mitigating Risk
Assessment with a CIRT Plan Lab
#10: Creating a CIRT Response Plan
for a Typical IT Infrastructure
Quiz / Homework
Assignment
Discussion
16
Final Evaluations
*SHORT WEEK* All assignments
must be completed by the last
day of the term by 5pm EST.
Final Exam
Syllabus Disclaimer
This syllabus contains important information critical to your success in this course. It
includes guidelines for this course and the instructor’s current expectations about
content, schedule, and requirements necessary for each student to achieve the best
educational results. While you must review and become familiar with the contents of
this syllabus, the instructor reserves the right to make adjustments or change in the
syllabus from time to time. Any changes to the syllabus will be discussed with the
students.