IMT4129

Risk Management for Information Security

Spring

Gjøvik

English

Overview

18 candidates

Average grade

B

3.83

0.19

Pass rate

100%

same

Grade distribution
Average over time
Pass rate over time

About this course

Content

  • Relationship to governance and management
  • Selected Risk Management Method(s)
  • Classifications of Risk Management methods
  • Risk, Threat and vulnerability discovery
  • Information security controls
  • Decision theory
  • Uncertainty quantification
  • Game theory
  • Other topics considered useful in the context of risk management for information security

Learning outcomes

The focus of this course is 'cost effective information security'. In particular, it addresses the following UN Sustainability Development Goals:

Goal 8, target 8.2: Achieve higher levels of economic productivity through diversification, technological upgrading and innovation, including through a focus on high-value added and labour-intensive sectors.

Goal 12: Sustainable consumption and production is about doing more and better with less. It is also about decoupling economic growth from environmental degradation, increasing resource efficiency and promoting sustainable lifestyles.

Having completed this course, the student will be able to contribute to employer performance with respect to both goal 8, target 8.2 and goal 12. After successfully completing the course, the students have obtained the following learning outcomes::

Knowledge:

  • Possesses advanced knowledge on the relationship between Management and Information Security Risk Management.
  • Possesses advanced knowledge on concepts and techniques utilized in selected information security risk management methods.
  • Possesses advanced knowledge of selected challenges facing the risk analyst.

Skills:

  • Is able to perform Information Security Risk Management tasks to support the overall organizational objectives.
  • Is able to justify Information Security Management decisions through deductive arguments based on sound scientific principles.
  • Is able to challenge established practices/views held by other practitioners.

General competence:

  • Advanced level of understanding of selected assumptions/principles and models on which risk analysis methods are/should be based.

Teaching methods

Lectures, Seminar(s), Group work, Project work, Reverse class-room, Multiple choice tests/quizzes, PBL, Presentation of student projects by students, Student/peer assessments.

The course includes one or more cases relating to AI in the context of information security risk management.

Mandatory activities are valid only for the term when they are completed.

Mandatory activities that each student is required to complete ahead of the exam:

  • EPN-OBLIG1: A scenario/case description must be submitted within 10 days of the first lecture.
  • EPN-OBLIG2: Several multiple choice/ quizzes must be completed with a score above a given threshold. Minimum requirement is 25% of max achievable score..
  • EPN-OBLIG3: Students must actively participate in at least 5 seminars through presentation of written material and participation in oral discussions. The students must document this participation in writing and hand in this documentation as part of their compulsory assignments.
  • EPN-OBLIG4: Students must complete 4 peer assessment 'rounds'. Each round includes handing in written material to be assessed and also completing assessments of hand-ins provided by fellow students. Hand-ins and assessments must be completed and handed in by deadlines provided by the course responsible..