Information Security Management (5cr)
Code: R0319-3005
General information
- Enrollment
- 23.11.2020 - 29.11.2020
- Registration for the implementation has ended.
- Timing
- 18.01.2021 - 31.07.2021
- Implementation has ended.
- Number of ECTS credits allocated
- 5 cr
- Local portion
- 0 cr
- Virtual portion
- 5 cr
- Mode of delivery
- Distance learning
- Campus
- Laurea Virtual Campus
- Teaching languages
- English
- Seats
- 20 - 40
- Degree programmes
- Complementary competence, bachelor's studies in English (CCN2), Information and Communication Technologies (ICT)
Learning outcomes
The student is able to
- evaluate the significance of different roles and the information security organization for the implementation of information security
 - evaluate information risks directed at organizations systematically and apply risk management practices
- design an information security management system for an organization
- identify the essential elements of the auditing process and evaluate the possibilities of auditing to develop information security in an organization
- apply standards in the development of information security in an organization
- draw contingency plans for information systems
                    
Teaching methods
- This study unit is fully online learning with the possibilities of volunteer tutoring meetings with the teachers.
- The tutoring meetings are not compulsory. Any student can participate tutoring meeting if they need any help from teachers.
- Virtual studies, weekly basis virtual learning and assignments
- NOTE: Student should finish compulsory ICT-studies before enrolling to complementary studies
- NOTE: Safety, Security and Risk Management students should take the study unit TO007BN Information and Cybersecurity Management after R0186 Information and Cybersecurity
-------------------------------------------------------------------------------------------------------------------------------------------------------------
- Learning material is based on Certified Information Security Manager (CISM) certification training material
- The study unit provides preparatory training for CISM but not certification exam
-------------------------------------------------------------------------------------------------------------------------------------------------------------
Study unit content:
Module-0: Induction and Study Plan
Module-1: Info Sec Governance Part 1
Module-2: Info Sec Governance Part 2
Module-3: Information Risk Management-1
Module-4: Information Risk Management-2
Module-5: Info Sec Program Dev Part 1
Module-6: Info Sec Program Dev Part 2
Module-7: Info Sec Incident Man Part 1
Module-8: Info Sec Incident Man Part 2
                    
Time and location
- Not dependent on place or time (virtual studies)
                    
Learning materials and recommended literature
- Learning material is based on Certified Information Security Manager (CISM) certification training material
- The study unit provides preparatory training for CISM but not certification exam
                    
Important dates
- Study unit starts on week 3 (preliminary plan)
- Study unit ends on week 13 (preliminary plan)
- Detailed schedule is released at the beginning of the study unit
- NOTE: There can be scheduling changes
                    
Forms of internationality
Teachers and students group are international (Finnish and English degree programme students). Study is suitable for exchange students.
                    
Student workload
- 5 cr / 137,5 hours
- Study unit will last 11 weeks
                    
Content and scheduling
Module-0: Induction and Study Plan
Module-1: Info Sec Governance Part 1
Module-2: Info Sec Governance Part 2
Module-3: Information Risk Management-1
Module-4: Information Risk Management-2
Module-5: Info Sec Program Dev Part 1
Module-6: Info Sec Program Dev Part 2
Module-7: Info Sec Incident Man Part 1
Module-8: Info Sec Incident Man Part 2
                    
Further information for students
- Study unit is suitable for any graduate level student. Considering following points:
o Student must know: how company/organization works
o Students knows the basics of ICT-technologies
o Student is able to study with weekly based schedule
- Any student who is willing to learn the overview of information security technologies, we recommend to participate following study unit: Introduction to Information Security
- The study unit is prioritized for TIKO and BIT students
- Safety, Security and Risk Management students should take the study unit TO007BN Information and Cybersecurity Management
- Inactive students are removed from the study unit after orientation period (the first week of the study unit)
                    
Evaluation scale
H-5
                    
Further information
- Study unit is suitable for any graduate level student. Considering following points:
o Student must know: how company/organization works
o Students knows the basics of ICT-technologies
o Student is able to study with weekly based schedule
- Any student who is willing to learn the overview of information security technologies, we recommend to participate following study unit: Introduction to Information Security
- The study unit is prioritized for TIKO and BIT students
- Safety, Security and Risk Management students should take the study unit TO007BN Information and Cybersecurity Management
- Inactive students are removed from the study unit after orientation period (the first week of the study unit)
                    
