Learning Objectives
5 objectives- Understand fundamental concepts, principles, and goals of information systems security.
- Develop and implement security policies and procedures adhering to regulatory compliance.
- Analyze and manage risks affecting information systems through systematic methodologies.
- Apply best practices in network security, cryptography, and secure software development.
- Recognize and address security challenges in cloud computing, mobile, IoT, and incident response.
Content Outline
PreviewUnit 3133: Information Systems Security
1. Introduction to Information Systems Security
- Importance of securing information systems
- Basic concepts: confidentiality, integrity, availability (CIA triad)
- Principles of information security
- Common threats and vulnerabilities
- Malware, phishing, insider threats
- Social engineering
- System and network vulnerabilities
2. Security Policies and Procedures
- Purpose and scope of security policies
- Developing effective security policies
- Access control mechanisms
- Authentication, authorization, accountability
- Data protection strategies
- Incident response planning
- Compliance with regulations and standards
3. Risk Management in Information Security
- Definition and importance of risk management
- Risk identification techniques
- Risk analysis and assessment methodologies
- Qualitative vs quantitative approaches
- Risk treatment strategies
- Avoidance, mitigation, acceptance, transfer
- Risk monitoring and review
4. Network Security
- Network security fundamentals
- Securing network devices (routers, switches, etc.)
- Network protocols and their security aspects
- Encryption technologies in networks
- Virtual Private Networks (VPNs)
- Firewalls: types and configurations
- Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS)
- Secure network configurations and best practices
5. Cryptography and Encryption
- Introduction to cryptography
- Symmetric vs asymmetric encryption algorithms
- Key management principles
- Digital signatures and certificates
- Secure communication protocols (SSL/TLS, IPSec)
- Ensuring confidentiality, integrity, and authenticity
6. Security in Cloud Computing
- Cloud computing overview and service models
- Unique security challenges in cloud environments
- Data protection in the cloud
- Access control in cloud services
- Compliance and regulatory considerations
- Shared responsibility model
- Secure cloud configuration and monitoring
7. Security Incident Response and Recovery
- Incident response framework and lifecycle
- Detection and identification of security incidents
- Incident handling procedures
- Forensics analysis basics
- Role and structure of incident response teams
- Recovery and post-incident activities
8. Secure Software Development
- Secure coding principles and guidelines
- Common software vulnerabilities (e.g., OWASP Top 10)
- Secure development lifecycle (SDLC)
- Static code analysis tools
- Dynamic code analysis and testing
- Best practices for preventing software exploits
9. Mobile and IoT Security
- Security challenges in mobile devices and applications
- Mobile malware and threats
- Mobile device management (MDM)
- Data protection on mobile platforms
- Security risks in Internet of Things (IoT) ecosystems
- Securing IoT devices and networks
10. Compliance and Legal Aspects of Information Security
- Overview of regulatory requirements
- Key industry standards and frameworks
- Privacy laws and their impact on security (GDPR, HIPAA, PCI DSS)
- Role of compliance in information security management
- Legal considerations and ethical issues
Unlock the full outline
Get the complete content outline, learning outcomes and assessment methods for Information Systems Security.
KSh 20 one-off, or included with a plan
Learning Outcomes
Unlock the outline above to see learning outcomes.
Assessment Methods
Unlock the outline above to see assessment methods.