Informatics Engineering

SECURITY MANAGEMENT SYSTEMS

General Data

Type of credits: ECTS
Number of credits: 7.50
Status: Mandatory
Type: Course
Academic Year:
Term:
Languages: English, Portuguese
Available for Mobility Students: No
Restricted to alliance: No
Code: Sin codigo

Coordination

Description

Theory
2

Theory/Practice
1

Laboratory
2

Instructors

Paulo Maio


 

Contents

The course syllabus is organized into interconnected modules and is based on a holistic and obliquus vision of security.
CP1. Information Security Management
- Standards and frameworks (e.g. ISO 27000, NIST)
- Life cycle
- Governance and organizational context
- Planning and Strategy
- Policies
- Programs and Projects
- People and Protection
CP2. Risk Management
- Identification
- Analysis
- Assessment
- Treatment
CP3. Impact Assessment
- Concepts
- Metrics
- Methods
CP4. Policies and Contingency Planning
- Incident response
- Disaster recovery
- Business continuity
- Crisis management
CP5. Laws, Ethics and Professional Codes
- Main national and international laws and regulations
- Ethical issues
- Professional Codes
CP6. Assessment of Information Security Management Systems
- Compliance with standards and legislation
- Internal and External Audit
- Audit for certification

Learning Outcomes

This course unit (UC) aims to provide students with the fundamental knowledge for the practice of information security management appropriate to the internal and external context of an organization and to the achievement of its business objectives (and/or mission). To this end, students are introduced with the typically life cycle of an information security management system as well as its main concepts and processes. In this context, students must acquire competences and skills related with the design, implementation and evaluation of (i) security policies; (ii) risk management; (iii) contingency plans; and (iv) assessing the impact of a security incident. Inherent to all these aspects, it is the need for (i) compliance with the organization's requirements and with current applicable legislation; and (ii) the adoption of standards and best practices.

After successfully completing this UC, students will be able to:
CO1. Discuss an information security management system with regard to its life cycle, processes and activities in the context of an organization (BL:4);
CO2. Develop security policies and procedures at different levels (e.g., organizational vs. system)(BL:6);
CO3: Apply risk management techniques to identify, analyze, evaluate, prioritize, treat and review risks on information assets (BL: 3);
CO4. Design policies and contingency plans to respond properly to incidents with different levels of severity (BL:6);
CO5. Assess the impact of security breaches (BL:5);
CO6. Explain the organizations compliance (or non-compliance) with the relevant legislation and/or regulations (BL: 5).