Information System Security Management
- Social Sciences
- 300 level
- 3 credit units
- 205 pages
- 20 units
This course introduces students to information gathering, technology security, access and control, methodology, and ethics in computer operations security. It explores Information Security Integration and models, Information Assurance into System Administration, Management Information Systems Useability and Associated Risk. The course also covers modern safety practices, warning signs in mitigating associated security threats, and various information systems assessments, risk options, and models.
About this course
- Difficulty
- Intermediate
- Study hours
- 200 hours
- Maths
- Basic
- Content
- Theoretical, case study
- Practical work
- No
- Assignments
- Tutor marked assessments
- Final examination
What you'll read
The real module and unit structure of CSS343, taken from the course material NOUN publishes.
- Unit 1: INFORMATION GATHERINGPage 19
- Unit 2: Information Security In The 21st Century: With Special Emphasis on Computer SecurityPage 26
- Unit 3: Introduction to System Analysis and DesignPage 37
- Unit 4: Information System Security: A Guide to the Use of Water Quality Management Principles IPage 46
- Unit 5 Information System Security: A Guide to the Use of Water Quality Management Principles IIPage 58
- UNIT 1: Ethics of Information Communication Technology (ICT)Page 75
- UNIT 2: Identity and Information Security IntegrationPage 81
- UNIT 3: Integrating Information Assurance into System AdministrationPage 93
- UNIT 4: Management Information Systems Usability and Associated RiskPage 97
- UNIT 5: Elevating Information Security to Business SecurityPage 104
- Unit 1 The Information Systems and the Economics of Innocent Fraud ManagementPage 108
- UNIT 2: An overview of Information Security as a risk management functionPage 121
- UNIT 3: RISK ASSESSMENTPage 127
- UNIT 4: RISK MITIGATION OPTIONSPage 151
- UNIT 5: Mitigating Economic Risk Through Security TechnologyPage 168
One paragraph, so you can see how it reads
CSS343 · Unit 1: INFORMATION GATHERING
The main sources of information are users of the system, forms and documents used in the organization, procedure manuals, rule books etc, reports used by the organization and existing computer programs(If Any).
What you should be able to do
- Explain information gathering in information system security
- Examine information systems usability and associated risk
- Understand measures in system analysis and design
- Explain the idea behind information security integration into system administration
- Appraise information security as a risk management function
- Understand the relevance of elevating information security to business security
What it prepares you for
- Security Analyst
- IT Manager
- Risk Manager
- Information Security Officer
- System Administrator
- Government
- Finance
- Healthcare
- Technology
- Consulting
Where it gets hard
The units students slow down on, and what makes each one heavy.
- Module 3:
Unit 5: Mitigating Economic Risk through Security Technology
Advanced calculus integration techniques are required to understand the economic models for optimal resource allocation.
- Module 1:
Unit 4: Information system security: a guide to the use of water quality management principles I
Understanding the complexities of water quality management principles requires a strong foundation in environmental science and engineering.
A suggested way through it
13 weeks, about 68 hours in total. Yours will differ.
- Week 1Module 1:
Unit 1: Information gathering · 4 hours
Understand the strategies and methods for information gathering.. Identify information sources and develop a method for obtaining information.. Learn about system requirements specification and its importance..
- Week 2Module 1:
Unit 2: Information security in the 21st century: with special emphasis on computer security · 4 hours
Examine the need for information security in the 21st century.. Understand the CIA (Confidentiality, Integrity, Availability) relationship.. Explore the modules and sub-modules of the information security chain..
Unit 3: Introduction to System Analysis and Design · 3 hours
Study the basic system components and their interdependencies.. Learn about the different phases of the system development life cycle.. Understand the components of system analysis and design..
- Week 3Module 1:
Unit 4: Information system security: a guide to the use of water quality management principles I · 5 hours
Understand the relevance and role of monitoring and information needs in water management.. Learn about the importance of integration in water resources management.. Examine the interactions between human activities and water resources..
- Week 4Module 1:
Unit 5: Information system security: a guide to the use of water quality management principles II · 5 hours
Understand the objective of an information system for water pollution control.. Learn about the types of data and information tools to be processed.. Examine the components of environmental management information systems..
- Week 5Module 2:
Unit 1: Ethics of information communication technology (ICT) · 5 hours
Comprehend key information concerning ethical issues regarding ICT.. Analyze and evaluate the impact of ICT on society.. Understand UNESCO's Info-Ethics Programme and its objectives..
- Week 6Module 2:
Unit 2: Identity and information security integration · 4 hours
Examine the historical perspective of identity and security.. Understand the need for identity and information security integration.. Learn about data discovery, classification, and security policy enforcement..
Unit 3: Integrating information assurance into system administration · 3 hours
Understand the types of services and facilities available to information system architects and administrators.. Learn about the information security implications of distributed computing.. Examine the security challenges in cloud computing environments..
- Week 7Module 2:
Unit 4: Management information systems usability and associated risk · 5 hours
Learn the basic definition of Management Information Systems.. Understand the relevance of MIS and how it should be designed.. Examine the various risks associated with the management of MIS..
- Week 8Module 2:
Unit 5: Elevating information security to business security · 5 hours
Understand that information security governance has an enterprise-wide risk mitigating impact.. Learn about the risks mitigated by an information security governance plan.. Explore the concept of elevating information security to business security..
- Week 9Module 3:
Unit 1: The information systems and the economics of innocent fraud management · 5 hours
Describe the connection between the use of ICTs and financial crime.. Understand the need for ICTs as a tool to fight the lack of transparency.. Examine the role of ICT in fraud and the clearing case..
- Week 10Module 3:
Unit 2: An overview of information security as a risk management function · 5 hours
Understand the concept of Risk management as a management responsibility.. Learn about the key roles of personnel in the risk management process.. Examine the integration of risk management into the SDLC..
- Week 11Module 3:
Unit 3: Risk assessment · 5 hours
Understand the various concepts such as vulnerability, threat sources, level of impact.. Appraise vulnerability in an IT system using the nine primary steps in risk assessment methodology..
- Week 12Module 3:
Unit 4: Risk mitigation options · 5 hours
Understand the various risk mitigation options and strategy.. Learn about the approaches for risk mitigation control, implementation, and control categories.. Examine the cost-benefit analysis in risk control..
- Week 13Module 3:
Unit 5: Mitigating economic risk through security technology · 5 hours
Define the components of risk mitigation through investment in security technology.. Understand the descriptive statistics that illuminate real-world occurrences.. Learn how to apply the numerical values in organizations..
Preparing for the exam
- Create concept maps linking Units 1-3 information gathering techniques.
- Practice data flow diagramming from Unit 1 weekly.
- Review the CIA triad (Confidentiality, Integrity, Availability) from Unit 2 and apply it to different scenarios.
- Study the phases of system development life cycle from Unit 3 and their importance.
- Focus on the ethical considerations in ICT from Unit 6, particularly privacy and security.
- Understand the different risk mitigation options from Module 3 and their applications.
- Review all TMAs and tutor feedback to identify areas of weakness.
Questions students ask about this course
What is CSS343 about?
This course introduces students to information gathering, technology security, access and control, methodology, and ethics in computer operations security. It explores Information Security Integration and models, Information Assurance into System Administration, Management Information Systems Useability and Associated Risk. The course also covers modern safety practices, warning signs in mitigating associated security threats, and various information systems assessments, risk options, and models.
How many units does CSS343 have?
CSS343, Information System Security Management, has 20 units across 4 modules, over 205 pages of course material. You can read it one unit at a time.
How many credit units is CSS343?
CSS343 carries 3 credit units, at 300 level in Social Sciences.
Is CSS343 hard?
CSS343 is rated intermediate level, with basic mathematical content. It is mostly theoretical and case study work.
How long does CSS343 take to study?
About 200 hours of study, spread across its 20 units.
How is CSS343 assessed?
CSS343 is assessed by assignments, tutor marked assessments and final examination.
What can I do with CSS343?
Security Analyst, IT Manager, Risk Manager, Information Security Officer and System Administrator.