IDATA2501

Information security

Spring and Autumn

Ålesund

Norwegian and English

Overview

7 candidates

Average grade

C

3.43

same

Pass rate

100%

same

Grade distribution
Average over time
Pass rate over time

About this course

Content

The foundation for information security

  • Terminology
  • Integrity, confidentiality and availability

Techological considerations regarding information security

  • Storage and use of digital information
  • Firewalls, backdoors, viruses, security breaches in applications
  • Security requirements to the systems
  • Risk management
  • Single point of failure, backup, physical safety measure
  • Problems addressing wireless
  • Cryptography and certificates

Organizational problems regarding information security:

  • Identify the human factor
  • Managements responsibilities for information security
  • Risk management and information assets management
  • Increase knowlegde regarding information security
  • The conflict between security and user friendly systems

Importance of anchoring security work in the entire organization: standards, laws and regulations.

Learning outcomes

Knowledge:

  • understand the meaning of information security
  • know and understand the key concepts within the area
  • know current threats to information security
  • have a good knowledge of the laws and regulations of the area
  • be familiar with recognized methods and standards for improved information security
  • have knowledge of relevant technical and organizational means to improve information security

Skills:

  • do a risk analysis for an hypothetical organization (case)
  • recommend appropriate and effective measures to improve information security
  • prepare a contingency plan for a hypothetical business (case)
  • establish adequate security in restricted operating environment (lab)

Competence:

  • be able to update their knowledge about information security
  • communicate their knowledge of information security also to persons without ICT background
  • be able to communicate on the subject with an organization's strategic management

Teaching methods

Teaching methods: Lectures, case studies and assignments

Mandatory activities: 3-5 mandatory assignments. All the mandatory assignments have to be approved in order to get access to the exam.