IMT1132
ntroduction to Information Security Risk Management
Last taught 2016
Spring and Autumn
Norwegian
About this course
Content
Project work
Information security and risk
Risk evaluation, analysis and assessment
Standards and guidelines
Information security management systems
Learning outcomes
Knowledge
The candidate can select an appropriate risk assessment methodology suitable for the complexity and documentation accuracy of an information system
Skills
The candidate can based on given guidelines or standards carry out a risk assessment on a given information system
The candidate can collaborate with system owners and supervisors and can adjust his or her practice based on their feedback
The candidate can find, assess and refer to information and material necessary to carry out a risk assessment
The candidate can use guidelines and standards to structure the implementation of information security in an organisation
General Competence
The candidate can carry out relatively complex projects in larger groups and accepts the necessity of tools and methods to carry out such tasks
The candidate is aware of the importance of mastering both oral and written communication depending on the target group (decision makers, colleagues and general public)
The candidate has gained ownership in a reference project where experience and view-points have been exchanged with collaborative partners and colleagues
Teaching methods
Forelesninger|Prosjektarbeid
Utfyllende informasjon:
The students are assigned to groups of 6 - 10 persons. Each group gets a task assigned from an external system owner. The projects are formulated such that the students have to carry out a risk assessment as the part of a project work. All projects report to a coordination team. The students get feedback on the group processes and their deliveries (Project plan, status reports, meeting agendas and minutes). Lectures and group assignments are run in parallel.