CSC-270 Principles of Information Security

This course is an introduction to the various technical and administrative aspects of Information Security and Assurance. This course provides the foundation for understanding the key issues associated with protecting information assets, determining the levels of protection and response to security incidents, and designing a consistent, reasonable information security system, with appropriate intrusion detection and reporting features. Students will be exposed to the spectrum of Security activities, methods, methodologies, and procedures, technical and managerial responses and an overview of the information security planning and staffing functions.

Credits

3

Lecture Contact Hours

3

Lab Contact Hours

0

Other Contact Hours

0

Department

  • Computer Science

Grading Scheme

  • Letter

SUNY Gen Ed Credit

  • No

Semesters Course Will Be Offered

  • Fall
  • Spring

Course Learning Outcomes

  1. Describe the legal, ethical, and professional issues in information security
  2. Demonstrate knowledge of security protocols
  3. Differentiate between different security devices and practices
View Course Outline

CSC 270: Principles of Information Security

Department

Computer Science

Course Description

This course is an introduction to the various technical and administrative aspects of Information Security and Assurance. This course provides the foundation for understanding the key issues associated with protecting information assets, determining the levels of protection and response to security incidents, and designing a consistent, reasonable information security system, with appropriate intrusion detection and reporting features. Students will be exposed to the spectrum of Security activities, methods, methodologies, and procedures, technical and managerial responses and an overview of the information security planning and staffing functions.

Credit Hours

3

Contact Hours

Lecture3
Lab0
Other0

Grading Scheme

Letter

Semester(s) Course Will Be Offered

Fall, Spring

Course Learning Outcomes

  1. Describe the legal, ethical, and professional issues in information security
  2. Demonstrate knowledge of security protocols
  3. Differentiate between different security devices and practices

Topic Outline

  1. Introduction to Information Security
  2. Security Investigation Phase
    1. The need for security
    2. Threats
    3. Attacks
  3. Legal, Ethical and professional issues in Info Security
    1. Relevant US Laws
    2. International Laws and legal bodies
    3. Policy vs. law
    4. Standards and practices
    5. Info Security blueprints
    6. Security architecture
  4. Planning for continuity
    1. Business impact analysis
    2. Incident response planning
    3. Incident reaction
    4. Incident recovery
    5. Disaster recovery planning
    6. Law enforcement involvement
  5. Physical Design
    1. Firewalls
    2. IDS
    3. Filters
    4. Cryptography and encryption –based solutions
    5. Access control devices