DCST2005

Risk Management

Spring

Trondheim

English

Overview

43 candidates

Average grade

B

3.95

0.18

Pass rate

100%

same

Grade distribution
Average over time
Pass rate over time

About this course

Content

  • Information security management Systems (ISMS)
  • Security work
  • The standards ISO 27001 and 27002.
  • Security policies, security culture and evaluation.
  • Risk management, including risk assessment and analysis.
  • Risk communication
  • Information classification and access control.
  • Incident response: planning and running.
  • Measuring security and key figures.
  • Outsourcing

Learning outcomes

Knowledge:

The candidate can:

  • explain the use of ISO 27001 and 27002, especially with regards to joint use and differences in information security management.
  • explain the importance of information security for a company's monetary and reputational value.
  • explain a stepwise plan for employing an ISMS, and show critical factors for each phase.
  • explain risk in an information security context, evaluate risk in information systems and make contingency plans.

Skills:

The candidate can:

  • make an assessment of strategy and measures for anchoring the safety work, based on a prior analysis of the situation in an example company
  • carry out a threat profiling and risk analysis for an example company based on a standard procedure, and prioritize and implement relevant measures with a focus on protecting identities
  • propose a strategy to involve both the company's own employees and any external expertise in the change processes related to the introduction of an ISMS
  • given guidelines or standards, carry out an information security risk assessment on a given information system

General competence:

The candidate can:

  • search for and apply relevant subject matter to shed light on a given problem
  • present security problems and solutions both in writing and orally

Teaching methods

Lectures, project work in larger groups, obligatory assignments, reflection, guidance meetings.

Complementary information: The students will be split into groups. Each group will work on an information security assignment with focus on risk assessments and a supporting ISMS.