Cyber Security & Risk Management syllabus
PEC-362D-IT · Third Year Information Technology, SPPU 2024 pattern. Every unit, the marks scheme, course outcomes and books, copied from the official syllabus PDF.
Unit-wise syllabus
Introduction To Cyber Security And Security Principles
9 hoursDerived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.
- Introduction to Cyber Security: Need, Importance and Challenges of Cyber Security, Cyberspace and Cyber Ecosystem, Information Security vs Cyber Security, Security Goals and Principles, CIA Triad, Cyber Threat Landscape.
- Security Concepts: Assets, Threats, Vulnerabilities, Exploits, Attack Surface, Security Controls, Security Policies and Procedures.
- Cyber Security Frameworks and Standards: Overview of Security Governance, Security Awareness and Training, Introduction to Cyber Security Frameworks and Best Practices.
- Case Studies: Analysis of a major cyber attack and its impact on an organization.
Preserved official unit paragraph
Introduction to Cyber Security: Need, Importance and Challenges of Cyber Security, Cyberspace and Cyber Ecosystem, Information Security vs Cyber Security, Security Goals and Principles, CIA Triad, Cyber Threat Landscape. Security Concepts: Assets, Threats, Vulnerabilities, Exploits, Attack Surface, Security Controls, Security Policies and Procedures. Cyber Security Frameworks and Standards: Overview of Security Governance, Security Awareness and Training, Introduction to Cyber Security Frameworks and Best Practices. Case Studies: Analysis of a major cyber attack and its impact on an organization.
Cyber Threats, Attacks and Security Controls
9 hoursDerived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.
- Cyber Threats and Attacks: Malware (Virus, Worm, Trojan Horse, Ransomware, Spyware), Phishing, Social Engineering, Password Attacks, Denial-of-Service (DoS) and Distributed DoS Attacks.
- Web and System Attacks: SQL Injection, Cross-Site Scripting (XSS), Man-in-the-Middle Attack, Session Hijacking, Insider Threats.
- Security Controls: Administrative, Technical and Physical Controls, Access Control Mechanisms, Security Monitoring and Logging.
- Emerging Threats: Cloud Security Threats, Mobile Security Threats, IoT Security Challenges.
- Case Studies: Investigation of a ransomware attack and mitigation strategies.
Preserved official unit paragraph
Cyber Threats and Attacks: Malware (Virus, Worm, Trojan Horse, Ransomware, Spyware), Phishing, Social Engineering, Password Attacks, Denial-of-Service (DoS) and Distributed DoS Attacks. Web and System Attacks: SQL Injection, Cross-Site Scripting (XSS), Man-in-the-Middle Attack, Session Hijacking, Insider Threats. Security Controls: Administrative, Technical and Physical Controls, Access Control Mechanisms, Security Monitoring and Logging. Emerging Threats: Cloud Security Threats, Mobile Security Threats, IoT Security Challenges. Case Studies: Investigation of a ransomware attack and mitigation strategies.
Network and Application Security
9 hoursDerived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.
- Network Security Fundamentals: Network Security Architecture, Secure Network Design, Common Network Vulnerabilities.
- Network Security Mechanisms: Firewalls, Proxy Servers, Virtual Private Networks (VPNs), Intrusion Detection and Prevention Systems (IDS/IPS), Network Segmentation.
- Application Security: Secure Software Development Life Cycle (SSDLC), Secure Coding Practices, Vulnerability Assessment and Penetration Testing Concepts.
- Data Security: Data Classification, Data Protection Techniques, Backup and Recovery Mechanisms.
- Case Studies: Security assessment of a web application and network infrastructure
Preserved official unit paragraph
Network Security Fundamentals: Network Security Architecture, Secure Network Design, Common Network Vulnerabilities. Network Security Mechanisms: Firewalls, Proxy Servers, Virtual Private Networks (VPNs), Intrusion Detection and Prevention Systems (IDS/IPS), Network Segmentation. Application Security: Secure Software Development Life Cycle (SSDLC), Secure Coding Practices, Vulnerability Assessment and Penetration Testing Concepts. Data Security: Data Classification, Data Protection Techniques, Backup and Recovery Mechanisms. Case Studies: Security assessment of a web application and network infrastructure
Cryptography, Authentication and Incident Response
9 hoursDerived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.
- Cryptography Fundamentals: Principles of Cryptography, Encryption and Decryption, Symmetric and Asymmetric Cryptography.
- Cryptographic Techniques: Hash Functions, Digital Signatures, Public Key Infrastructure (PKI), Digital Certificates.
- Authentication and Access Management: Authentication Methods, Multi-Factor Authentication (MFA), Authorization and Identity Management.
- Incident Response: Security Incident Lifecycle, Detection, Containment, Eradication, Recovery, Incident Reporting and Documentation.
- Case Studies: Analysis of a security breach and incident response process
Preserved official unit paragraph
Cryptography Fundamentals: Principles of Cryptography, Encryption and Decryption, Symmetric and Asymmetric Cryptography. Cryptographic Techniques: Hash Functions, Digital Signatures, Public Key Infrastructure (PKI), Digital Certificates. Authentication and Access Management: Authentication Methods, Multi-Factor Authentication (MFA), Authorization and Identity Management. Incident Response: Security Incident Lifecycle, Detection, Containment, Eradication, Recovery, Incident Reporting and Documentation. Case Studies: Analysis of a security breach and incident response process
Cyber Risk Management and Security Governance
9 hoursDerived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.
- Cyber Risk Management: Risk Concepts, Risk Identification, Risk Assessment, Risk Analysis, Risk Evaluation and Risk Prioritization.
- Risk Treatment Strategies: Risk Avoidance, Risk Mitigation, Risk Transfer and Risk Acceptance, Risk Register and Risk Monitoring.
- Governance and Compliance: Security Governance Principles, Cyber Laws and Regulations, Compliance Requirements, Ethics in Cyber Security.
- Business Continuity and Disaster Recovery: Business Continuity Planning (BCP), Disaster Recovery Planning (DRP), Backup Strategies, Recovery Objectives and Testing of Recovery Plans.
- Case Studies: Risk assessment and business continuity planning for an organization
Preserved official unit paragraph
Cyber Risk Management: Risk Concepts, Risk Identification, Risk Assessment, Risk Analysis, Risk Evaluation and Risk Prioritization. Risk Treatment Strategies: Risk Avoidance, Risk Mitigation, Risk Transfer and Risk Acceptance, Risk Register and Risk Monitoring. Governance and Compliance: Security Governance Principles, Cyber Laws and Regulations, Compliance Requirements, Ethics in Cyber Security. Business Continuity and Disaster Recovery: Business Continuity Planning (BCP), Disaster Recovery Planning (DRP), Backup Strategies, Recovery Objectives and Testing of Recovery Plans. Case Studies: Risk assessment and business continuity planning for an organization
Marks and credits
| Head | Marks | Credit |
|---|---|---|
| CCE (continuous comprehensive evaluation) | 30 | 3 |
| End-semester exam | 70 |
Prerequisite: Computer Networks, Operating System.
Course outcomes
- CO1To explain the fundamental concepts of cybersecurity, information security principles, threats, vulnerabilities, and security controls.
- CO2To analyze various cyber threats, attacks, and vulnerabilities and recommend suitable protection mechanisms.
- CO3To apply network security, application security, cryptographic techniques, and authentication mechanisms to enhance system security.
- CO4To perform basic security assessment activities and implement appropriate incident response procedures for security incidents.
- CO5To evaluate cybersecurity risks and apply governance, compliance, business continuity, and disaster recovery strategies to improve organizational resilience.
Books
Text books
- Charles J. Brooks, Christopher Grow, Philip Craig Jr., Donald Short, “Cyber Security Essentials”, McGraw-Hill Education.
- Michael E. Whitman, Herbert J. Mattord, “Principles of Information Security”, Cengage Learning.
Reference books
- William Stallings, Lawrie Brown, “Computer Security: Principles and Practice”, Pearson Education.
- William Stallings, “Cryptography and Network Security: Principles and Practice”, Pearson Education.
- Mark Stamp, “Information Security: Principles and Practice”, Wiley India.
- Michael E. Whitman, Herbert J. Mattord, “Risk Management and Information Security”, Cengage Learning.
FAQ
How many units are in Cyber Security & Risk Management?
Cyber Security & Risk Management (PEC-362D-IT) has 5 units and 45 hours of theory: Unit I Introduction To Cyber Security And Security Principles (9 h); Unit II Cyber Threats, Attacks and Security Controls (9 h); Unit III Network and Application Security (9 h); Unit IV Cryptography, Authentication and Incident Response (9 h); Unit V Cyber Risk Management and Security Governance (9 h).
What is the marks scheme for Cyber Security & Risk Management?
The official Information Technology 2024 pattern syllabus lists continuous comprehensive evaluation (CCE) for 30 marks and the end-semester exam for 70 marks, for 3 credits.
What should I know before Cyber Security & Risk Management?
Prerequisite listed in the syllabus: Computer Networks, Operating System.