IMT4127
Security Management Metrics
Spring
Gjøvik
English
About this course
Content
- Introduction- Corporate and IT Governance - Transparency, Ownership and Control in Information and Cybersecurity - Security Governance and Investment Management
- Measuring and Assessing - Maturity Models - Measurement Systems- Compliance - Exercises on these topics
- Case Study on Metrics Maturity Assessment (in collaboration with Center for Cyber and Information Security partner)
- Standards and Best Practices- COBIT 5 for Information Security- ISO 27001 (ISMS) / ISO 27002 (Controls) / ISO 27004 (Measurement) / ISO 27014 (Governance), NIST 800-55
- Simulation models and metrics application
Learning outcomes
Security Management Metrics do not exist "per se", but are based on IT and operational risk management methods, definition and measurement of security governance, and the subsequent design, implementation and operation of an appropriate level of organizational and technical measurement system. This course provides an overview of IT and Security Governance, Security Metrics and Measurements, Standards and Measurement System and their dependencies in general, and the information security standards Cobit 5 for Information Security, NIST 800-55 and ISO 27001 / ISO 27002 in particular.
After attending the course, candidates should possess the following:
Knowledge
- Understanding of security management as a critical component of IT and corporate governance, including its role as a continuous improvement process and investment area.
- Knowledge of the basic concepts of COBIT 5, NIST 800-55, and the ISO/IEC 270xx standards.
- A basic understanding of the design, implementation, and evaluation of maturity models for security.
Skills
- Ability to apply principles for designing, implementing, and auditing an Information Security Management System (ISMS) using strategic, tactical, and technical building blocks.
- Ability to design an appropriate level of Security Governance and Information Security for a given organizational context, and to express this using a suitable maturity model.
General Competence
- Understanding of the main principles, functions, and interdependencies of IT governance.
- Ability to interpret and apply metrics at strategic, tactical, and operational levels.
- Knowledge of security reporting, measurement techniques, and relevant international standards.
Teaching methods
- Lectures
- Assignments
- Project work
Additional information:
- The course will be made accessible for campus, remote and part-time students. Every student is free to choose the pedagogic arrangement form that is best fitted for her/his own requirement. The lectures in the course will be mostly given on campus (Gjøvik) and are open for both categories of students. All the lectures will also be available on Internet through NTNU's learning management system.
- Lectures, exercises and homework in between lecture blocks.
Compulsory requirements:
- The course requires active participation in projects - both in class and outside class.
The course is also available to Master in digital Building processes / "Bygg- og miljøteknikk" track "digitale byggeprosesser", and to students in the Master of Industrial Innovation and Digital Security (MIIDS) (campus Gjøvik Master's only).