DCST2005
Risk Management
Spring
Trondheim
English
About this course
Content
- Information security management Systems (ISMS)
- Security work
- The standards ISO 27001 and 27002.
- Security policies, security culture and evaluation.
- Risk management, including risk assessment and analysis.
- Risk communication
- Information classification and access control.
- Incident response: planning and running.
- Measuring security and key figures.
- Outsourcing
Learning outcomes
Knowledge:
The candidate can:
- explain the use of ISO 27001 and 27002, especially with regards to joint use and differences in information security management.
- explain the importance of information security for a company's monetary and reputational value.
- explain a stepwise plan for employing an ISMS, and show critical factors for each phase.
- explain risk in an information security context, evaluate risk in information systems and make contingency plans.
Skills:
The candidate can:
- make an assessment of strategy and measures for anchoring the safety work, based on a prior analysis of the situation in an example company
- carry out a threat profiling and risk analysis for an example company based on a standard procedure, and prioritize and implement relevant measures with a focus on protecting identities
- propose a strategy to involve both the company's own employees and any external expertise in the change processes related to the introduction of an ISMS
- given guidelines or standards, carry out an information security risk assessment on a given information system
General competence:
The candidate can:
- search for and apply relevant subject matter to shed light on a given problem
- present security problems and solutions both in writing and orally
Teaching methods
Lectures, project work in larger groups, obligatory assignments, reflection, guidance meetings.
Complementary information: The students will be split into groups. Each group will work on an information security assignment with focus on risk assessments and a supporting ISMS.