CS812 - Information Security Fundamentals
| TIMETABLE | TEACHING MATERIAL |
| Credits | 15 |
| Level | 5 |
| Semester | Term 1 |
| Availability | Not available as an elective. |
| Prerequisites | None |
| Learning Activities Breakdown | Two campus days, 4 online Q&A sessions, online study and assignment preparation. |
| Items of Assessment | 3 |
| Assessment | 100% by coursework. An individual assignment 45%, a group assignment 45%, and participation 10% (online quizzes). |
| ILO Assessment Mapping | |
| Pedagogical Methods Used to Support Competency Development | |
| Resit | 100% by coursework. |
| Lecturer | Sotirios Terzis |
Aims and Objectives
The aim of this module is to act as an introduction to information security by introducing key concepts, such as vulnerability, threat, attack and exploit, control, risk, risk landscape, residual risk, privacy, and their relationships; the main security mechanisms, authentication, access control and cryptography; and the organizational context within which information security activities take place, covering aspects such as information security culture, the role of policy and standards, the business environment, business resilience, and the legal and regulatory environment.
Learning Outcomes
At the end of this class learners should be able:
- To understand the meaning of information security, key associated concepts, their relationships, and how these apply to their organisation.
- To appreciate how encryption, user authentication and access control can be used individually or in combination to meet particular information security requirements, taking into consideration the particular context of their organisation and the strengths and weaknesses of specific techniques.
- To appreciate that information security needs to be explicitly managed in accordance with international standards and industry guidelines, and the range of activities that such management entails and how these could be applied to their organisation.
- To understand the importance of risk management to effective information security, and how to select and apply standard industry techniques to manage information security risks within the context of their organisation.
- To appreciate that information security is shaped by the regulatory and legal context within which organisations operate, the provisions of key legislation and regulations, and the information security requirements they prescribe.
Syllabus
Key information security concepts like: confidentiality, integrity, availability, threat, vulnerability, attack, risk, etc and their relationships
Symmetric and Asymmetric Cryptography, Message Authentication Codes, Secure Hashing, Random and Pseudo-random Numbers
User Authentication using Passwords, Biometrics and Tokens, Authentication Attacks and Defences
Access Control; Discretionary, Mandatory, Role-based and Attribute-Based Access Control
IT security management, Information Security Policy, Security Risk Assessment, IT Security planning, implementation and monitoring, IT and Security Management Standards (ISO 27000, ISO 27002, ISO13335, NIST SP800-53, Physical and Infrastructure Security, Human Resource Security, Cyber Resilience
Law, ethics, professionalism & ethical practice; Cybercrime & Computer Misuse; Intellectual Property; Privacy, data protection & workplace monitoring; Freedom of Information
Recommended Reading
This list is indicative only – the class lecturer may recommend alternative reading material. Please do not purchase any of the reading material listed below until you have confirmed with the class lecturer that it will be used for this class.
- W. Stallings and L. Brown, Computer Security: Principles and Practice, 5th eds., Pearson, 2024.
- A. Taylor, D. Alexander, A. Finch, and D. Sutton, Information Security Management Principles, 4th edition, BCS, 2024
- D. Sutton, Information Risk Management: A practitioner’s guide, 2nd edition, BCS, 2021
- D. Rowland, U. Kohl & A. Charlesworth, A. Information technology law 5th edition. Routledge, 2016.
- H. Nissenbaum. Privacy in Context: Technology, Policy, and the Integrity of Social Life. Stanford University Publishing, 2010.
- P. Voigt, and A.V. Dem Bussche. The EU General Data Protection Regulation (GDPR) : A Practical Guide / Cham: Springer International Publishing, 2017.
Last updated: 2026-07-06 11:48:24