CSC-270 Principles of Information Security
This course is an introduction to the various technical and administrative aspects of Information Security and Assurance. This course provides the foundation for understanding the key issues associated with protecting information assets, determining the levels of protection and response to security incidents, and designing a consistent, reasonable information security system, with appropriate intrusion detection and reporting features. Students will be exposed to the spectrum of Security activities, methods, methodologies, and procedures, technical and managerial responses and an overview of the information security planning and staffing functions.
For more detailed course information view the
Course Outline
Department
Computer Science
Course Description
This course is an introduction to the various technical and administrative aspects of Information Security and Assurance. This course provides the foundation for understanding the key issues associated with protecting information assets, determining the levels of protection and response to security incidents, and designing a consistent, reasonable information security system, with appropriate intrusion detection and reporting features. Students will be exposed to the spectrum of Security activities, methods, methodologies, and procedures, technical and managerial responses and an overview of the information security planning and staffing functions.
Credit Hours
3Semester(s) Course Will Be Offered
Fall, Spring
Course Learning Outcomes
- Describe the legal, ethical, and professional issues in information security
- Demonstrate knowledge of security protocols
- Differentiate between different security devices and practices
Topic Outline
- Introduction to Information Security
- Security Investigation Phase
- The need for security
- Threats
- Attacks
- Legal, Ethical and professional issues in Info Security
- Relevant US Laws
- International Laws and legal bodies
- Policy vs. law
- Standards and practices
- Info Security blueprints
- Security architecture
- Planning for continuity
- Business impact analysis
- Incident response planning
- Incident reaction
- Incident recovery
- Disaster recovery planning
- Law enforcement involvement
- Physical Design
- Firewalls
- IDS
- Filters
- Cryptography and encryption –based solutions
- Access control devices