IMT4115

Introduction to Information Security Management

Autumn

Gjøvik

English

Overview

89 candidates

Average grade

D

2.38

0.35

Pass rate

91%

5 points

Grade distribution
Average over time
Pass rate over time

About this course

Content

  • Introduction to Information security strategy and policy management
  • Cultural, organizational and behavioral theories used in information security management organizations.
  • Legal and ethical aspects of information security and privacy management.
  • Overview of current information security management standards and practices
  • How to develop a security program
  • Introduction to assess and treat risk: Threat and vulnerability modelling
  • Management models and management practices
  • Contingencies and maintenance of Information security
  • Information security emergency preparedness planning and incident management

Learning outcomes

Knowledge:

The candidate possesses through knowledge of the fundamental theories models practice information security management for both large and small organizations. The candidate possesses insight and understanding of ethical and legal aspects within information security management and privacy management. The candidate possesses a good understanding of the risk management processes. The candidate possesses a good understanding of security planning and incident management process. The candidate possesses insight and good understanding of security awareness and security escalations issues in information security management work. The candidate possesses insight into the technological innovation process in IT security and its effect on security management. The candidate possesses basic knowledge of the standards in information security management.

Skills: The candidate is capable to analyze existing theory, models and methods in the field of information security management and work independently on solving theoretical and practical problems. The candidate is capable to apply his/her knowledge to both modeling the potential problems and the solutions in information security management and be able to communicate these problems and solutions using basic theoretical skills. The candidate is capable to use basic terminology and is aware of the basic standards used in the field of information security management.

General competence: Can participate in group work and manage different organization roles of information security management.

Teaching methods

The course will be made accessible for both campus and remote students. Every student is free to choose the pedagogic arrangement form that is best fitted for her/his own requirement. The lectures in the course will be given on campus Gjøvik, and are open for the different categories of students. All the lectures will also be available on Internet through the NTNU learning management system Canvas.

- Lectures are based on the book and other relevant literature and examples.

- There are group work with assignments (risk-analysis case, crisis management discussion exercise and term-paper)

- Self-reflection on group work regarding term-paper

The risk-analysis case (SOHO) is a mandatory assignment, where you work in groups of 2-3.

The crisis management discussion exercise require mandatory attendance, and are set up as a group exercise based on the term-paper group.

The risk-analysis work and the crisis management discussion exercise are mandatory assignments, and you will not be able to attend the exam if you haven't got the risk-analysis assignment approved and attended the exercise.

For the term-paper the deliveries are:

- Sign up for wanted book-project

- Create a schedule with shared management responsibilities

- Deliver book-project work plan included problem description and research questions for each chapter, included the shared management responsibilities

- Voluntary mid-term review

- Submission deadline by email: Selected responsible (by the group) deliver the full book-project by email to supervisor.

- Submission deadline in Inspera: Everyone delivers only their own contribution (term-paper/book-chapter) together with self-assessment/reflection.

The written exam is a school exam at the University.