ID302809

Information security

Last taught 2021

Autumn

Ålesund

Norwegian and English

Overview

19 candidates

Average grade

C

3.21

0.11

Pass rate

100%

2 points

Grade distribution
Average over time
Pass rate over time

About this course

Content

The foundation for information security
- terminology
- integrity, confidentiality and availability

Techological considerations regarding information security
- Storage and use of digital information
- Firewalls, backdoors, viruses, security breaches in applications
- Security requirements to the systems
- Risk management
- Single point of failure, backup, physical safety measure
- Problems addressing wireless
- Cryptography and sertificates 

Organizational problems regarding information security
- Identify the human factor
- Managements responsibilities for information security
- Risk management and information assets management
- Increase knowlegde regarding information security
- The conflict between security and user friendly systems

Importance of anchoring security work in the entire organization
- Standards, laws and regulations

Learning outcomes

Knowledge:
- understand the meaning of information security
- know and understand the key concepts within the area
- have a good understanding of the value of information and information systems in organizations
- know current threats to information security
- have a good knowlede og the laws and regulations of the area
- be familiar with recognized methods and standards for improved information security
- have knowledge of relevant technical and organizational means to improve information security

Skills:
- do a risk analysis for an hypotetical organization (case)
- recommend appropriate and effective measures to improve information security
- prepare a contingency plan for a hypotetical business (case)
- establish adequate security in restricted operating environment (lab)

Competence:
- be able to update their knowledge about information security
- communicate their knowledge of information security also to persons without ICT background
- be able to communicate on the subject with an organization's stratecic management

Teaching methods

teaching methods:
Lectures, casestudies and assignments 

Mandatory work requirements:
All mandatory casestudies/assignments and the termpaper are to be delivered in time to get an assessment.
Students

Mandatory activities:
3-5 mandatory assignments. All the mandatory assignments have to be approved in order to get access to the exam, and they are part o the portfolio.