DCSG2005

Risk Management

Spring

Gjøvik

Norwegian

Overview

96 candidates

Average grade

C

3.46

0.42

Pass rate

95%

5 points

Grade distribution
Average over time
Pass rate over time

About this course

Content

Information Security Management:

  • Information Security Management Systems (ISMS)
  • Frameworks for security work and security management
  • NSM's basic principles in ICT security and security management
  • Standards 27001, 27002, and 27005
  • Security policy and evaluation

Risk management process:

  • Defining scope
  • Information classification and access control
  • Risk assessment and analysis, including asset, threat, and vulnerability
  • Security mechanisms and risk handling
  • Risk communication
  • Incident handling, planning, and execution
  • Security measurements and key figures

Sustainability:

DCSG2005 supports goal number 9 by contributing to ensuring industry, innovation, and infrastructure, as well as protecting trade secrets and innovations. The subject also contributes to goal 16, Peace, Justice, and Strong Institutions, by making it more difficult to succeed in cyber attacks.

Learning outcomes

Knowledge

  • Understanding and explaining the general principles of security management and control within digital security.
  • Understanding risk in an information security context and the purpose of risk management.
  • Knowing how to perform risk assessments and audits of information systems.
  • Understanding the application areas for international security and privacy standards.
  • Understanding and explaining the need for security requirements in a case study.

Skills

  • Conducting an information security risk assessment on a given information system based on guidelines or standards.
  • Collaborating with system owners and managers, adjusting practices and results based on their feedback.
  • Presenting security issues and solutions to both employees and managers.

General Competence

  • Leading and contributing to security work in a team consisting of individuals with different expertise and skills.
  • Conducting information security risk assessments.
  • Having knowledge of information security management and control.
  • Understanding the importance of both oral and written communication skills in explaining security issues and solutions to system owners and users, both face-to-face and online.

Teaching methods

  • Lectures
  • Group work
  • Online learning support
  • Mandatory tasks

Additional information: Students are divided into groups and assigned tasks based on information security. Projects involve risk assessments and audits of current and future systems.