Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| risk_and_information_management [2020/03/17 16:27] – created bob | risk_and_information_management [2025/08/27 08:38] (current) – [Module UFCFMU-30-3 Level 6 30 credits] mark | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== Risk and information management ====== | ====== Risk and information management ====== | ||
| - | ==== Module | + | ==== Module |
| - | ===== All information on this page is subject to validation and may change ===== | + | === Module team leader: Anisa Elezi === |
| - | === Module team leader: Leonard Shand === | + | {{:cyberdegree: |
| - | {{ : | ||
| ==== Overview ==== | ==== Overview ==== | ||
| Risk assessments are used to identify, estimate, and prioritize risk to organisational operations (i.e., mission, functions, image, finance and reputation), | Risk assessments are used to identify, estimate, and prioritize risk to organisational operations (i.e., mission, functions, image, finance and reputation), | ||
| + | |||
| In order to assess risk, the systems need to be explored for weaknesses, either technical or social. Reconnaissance methods emulate those of attackers. | In order to assess risk, the systems need to be explored for weaknesses, either technical or social. Reconnaissance methods emulate those of attackers. | ||
| + | |||
| This module examines: | This module examines: | ||
| *the methods and roles of those involved in attacking systems | *the methods and roles of those involved in attacking systems | ||
| *analysing system weaknesses | *analysing system weaknesses | ||
| *assessing the associated risks and managing them | *assessing the associated risks and managing them | ||
| - | |||
| - | |||
| You will cover: | You will cover: | ||
| - | *information | + | *the role of information |
| - | | + | *behavioural analysis |
| - | | + | *the motivations and ways of thinking of different classes of threat actors, criminal intent, activism, state actors, hackers, and how this drives the behaviour of the threat actors |
| - | | + | *tailoring mitigations for the different classes of threat actor |
| - | *database concepts, e.g.: | + | *social engineering and phishing |
| - | *components | + | *insider threat |
| - | | + | *malicious intent and human error |
| - | | + | *usable security |
| - | *big data, e.g.: | + | *creation |
| - | *benefits and limitations | + | *how threat actors’ actions appear in typical sources |
| - | *components and architectures employed in systems for big data (e.g. Hadoop cluster) | + | *sourcing intelligence ethically so that it may be used as required |
| - | *tools and techniques for analysing large heterogeneous data sets, including statistics | + | *methods attackers/ |
| - | | + | *phishing |
| - | *key concepts | + | *exploiting an insider |
| - | *internationally recognised standards – e.g., ISO27001, or similar | + | *port scanning |
| - | *governance, organisational structure, roles, policies, standards and guidelines for cyber and information | + | *open source intelligence |
| - | *how an organisation’s security policies, standards and governance are supported by provisioning and access rights – e.g., how identity and access management are implemented and maintained for a database application or physical access control | + | *asset valuation |
| - | *how cyber security policies | + | *risk analysis methodologies in common use |
| - | *the roles of experts in the cyber security industry, how they are recognised, and the work they do. | + | *risk appetite |
| - | *how to use organisations | + | *economics of security |
| + | *different ways of treating risk (mitigate, transfer, accept etc.) | ||
| + | *principles of system risk modelling | ||
| + | *an enterprise modelling technique such as UML | ||
| + | *risk assessment | ||
| + | *approaches to risk treatment (mitigate, transfer, accept, etc.) | ||
| + | *risk management in practice | ||
| + | | ||
| + | *description of risk in qualitative, | ||
| + | *role of risk owner, contrasting role with other stakeholders | ||
| Line 48: | Line 57: | ||
| The full assignment brief will be placed here when it is issued | The full assignment brief will be placed here when it is issued | ||
| - | === Component A: Practical portfolio | + | === Component A: Oral Examination |
| - | Issued: | + | Issued: |
| Due: Start of block release week 3 | Due: Start of block release week 3 | ||
| - | Part 1: Apprentices will design, create and use a database through | + | Apprentices will be provided with a case study of a system |
| - | Part 2: Apprentices will extract | + | This assessment also serves as a preparation for an End-Point-Assessment. |
| - | === Component B: Presentation (30 minutes) | + | === Component B: Report |
| Issued: End of block release week 3 | Issued: End of block release week 3 | ||
| Line 64: | Line 73: | ||
| Due: Start of block release week 1 of next module | Due: Start of block release week 1 of next module | ||
| - | A presentation of an information security plan for the apprentice’s organisation. It should cover: | + | Apprentices will undertake a research-based assignment in which they investigate |
| - | *Compliance with ISO27001 | + | |
| - | *The organisation’s | + | |
| - | *The use of CERT and OSINT | + | |
| Line 76: | Line 82: | ||
| ==== Submission details ==== | ==== Submission details ==== | ||
| - | To be added | + | All assignments will be submitted and feedback given on the UWE Blackboard system |
| - | ==== Reading | + | ==== Reading |
| - | To be added | + | [[https:// |
| ==== Communication ==== | ==== Communication ==== | ||
| - | All questions about this module, after the course commences, | + | All questions about this module should be directed to the module leader. |
| Please contact via email, which is monitored continuously | Please contact via email, which is monitored continuously | ||
| - | ==== Advice and support ==== | ||
| - | To be added | ||