Relate course work to the current job responsibilities

profileLakshmi143
-Info-SecurityRisk-Mgmt_coursework.pdf

School of Computer and Information Sciences

COURSE SYLLABUS

Course Information

ISOL533 - M51 Info Security & Risk Mgmt

Fall 2020 Full Term

Course Format: Hybrid

CRN: 11719

Class Time and Location: F 08:00 AM - 10:00 PM, DAL

Residency Session: 10/09/2020 - 10/11/2020 

Instructor Information

Name: Olatunji Arowolo

Email: [email protected]

Phone: 817-821-4486

Office Location: Virtual

Office Hours/Preferred Contact Times: By Appointment only

Course Description

The course provides a methodology to identify an institution�s information technology

assets, the proper way to determine the necessary level of protection required, and

techniques for developing budgets for security implementations. Credit, 3 hrs.

Course Objectives

Upon completion of this course:

Describe the components of an effective organizational risk management

program.

Describe the process of performing risk assessments.

Identify assets and activities to protect within an organization.

SU013KA
Highlight

Explain the basic concepts of and need for risk management.

Learner Outcomes

Outcome 2.3: Students examine risk management strategies for protecting

assets.

Course Website

Access to the course website is required via the iLearn portal on the University of the

Cumberlands website: http://www.ucumberlands.edu/ilearn/ 

or https://ucumberlands.blackboard.com/

Required Books and Resources

Title: Managing Risk in Information Systems

Subtitle: **PLEASE SEE BOOKSTORE LINK BELOW TO PURCHASE

REQUIRED MATERIALS

Authors: Darril Gibson

Publisher: Jones & Bartlett Publishers

Publication Date: 2014-07-01

Course Required text can be found and purchased via the UC Barnes and Noble

Bookstore: https://cumber.bncollege.com/shop/cumberlands/page/find-textbooks

Requirements and Policies

Academic Integrity/Plagiarism

At a Christian liberal arts university committed to the pursuit of truth and

understanding, any act of academic dishonesty is especially distressing and cannot be

tolerated. In general, academic dishonesty involves the abuse and misuse of

information or people to gain an undeserved academic advantage or evaluation. The

common forms of academic dishonesty include:

Cheating – using deception in the taking of tests or the preparation of written

work, using unauthorized materials, copying another person’s work with or without

consent, or assisting another in such activities.

Week Topic & Reading Assignments

1

Introduction to Course

 

 

Chapter 1: Risk Management

Fundamentals Lab #1: Identifying

Threats and Vulnerabilities in an IT

Infrastructure

Welcome Discussion

Quiz / Homework

Assignment

 

 *Failing to Participate in

Week 1 may result in being

dropped from the course. 

2

Chapter 3: Managing Compliance

Lab #2: Aligning Risks, Threats,

and Vulnerabilities to COBIT P09

Quiz / Homework

Assignment 

3

Chapter 2: Managing Risk: Threats,

Vulnerabilities, and Exploits

Quiz / Homework

Assignment

Discussion

4

Chapter 4: Developing a Risk

Management Plan Lab #3: Defining

Scope & Structure for an IT Risk

Management Plan

Quiz / Homework

Assignment

5

 

 

Chapter 5: Defining Risk

Assessment Approaches Chapter 6:

Performing a Risk Assessment Lab

#4: Performing a Qualitative Risk

Assessment

Quiz / Homework

Assignment

6

Required Residency Session Group Research Paper

Presentation &

Practical Connection

Assignment

7

Chapter 7: Identifying Assets and

Activities to be Protected Lab #5:

Identifying Risks, Threats,

Vulnerabilities using Zenmap® GUI

(Nmap) and Nessus® Reports

Quiz / Homework

Assignment

8

Chapter 8: Identifying/Analyzing

Threats, Weaknesses, and Exploits

Midterm Exam 

9

Chapter 9: Identifying/Analyzing

Risk Mitigation Security Controls

Quiz / Homework

Assignment

10

Chapter 10: Planning Risk

Mitigation Throughout Your

Organization

Quiz / Homework

Assignment

11

Chapter 11: Turning Risk

Assessment into a Risk Mitigation

Plan Lab #6: Developing a Risk-

Mitigation Plan Outline 

Quiz / Homework

Assignment

12

Chapter 12: Mitigating Risk with a

Business Impact Analysis Lab #7:

Performing a Business Impact

Analysis

Quiz / Homework

Assignment

13

Chapter 13: Mitigating Risk with a

Business Continuity Plan Lab #8:

Performing a Business Continuity

Plan

Quiz / Homework

Assignment

Discussion

14

Chapter 14: Mitigating Risk with a

Disaster Recovery Plan Lab #9:

Developing Disaster Recovery

Procedures & Recovery Instructions

Quiz / Homework

Assignment

15

Chapter 15: Mitigating Risk

Assessment with a CIRT Plan Lab

#10: Creating a CIRT Response Plan

for a Typical IT Infrastructure

Quiz / Homework

Assignment

Discussion

16

Final Evaluations 

*SHORT WEEK* All assignments

must be completed by the last

day of the term by 5pm EST. 

Final Exam

Syllabus Disclaimer

This syllabus contains important information critical to your success in this course. It

includes guidelines for this course and the instructor’s current expectations about

content, schedule, and requirements necessary for each student to achieve the best

educational results. While you must review and become familiar with the contents of

this syllabus, the instructor reserves the right to make adjustments or change in the

syllabus from time to time. Any changes to the syllabus will be discussed with the

students.