Cyber Security & Risk Management syllabus

PEC-362D-IT · Third Year Information Technology, SPPU 2024 pattern. Every unit, the marks scheme, course outcomes and books, copied from the official syllabus PDF.

PEC-362D-IT3 h/week theoryCCE 30 + End-sem 70
45hours of theory
05.units
03.credits

Unit-wise syllabus

UNIT I

Introduction To Cyber Security And Security Principles

9 hours

Derived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.

  • Introduction to Cyber Security: Need, Importance and Challenges of Cyber Security, Cyberspace and Cyber Ecosystem, Information Security vs Cyber Security, Security Goals and Principles, CIA Triad, Cyber Threat Landscape.
  • Security Concepts: Assets, Threats, Vulnerabilities, Exploits, Attack Surface, Security Controls, Security Policies and Procedures.
  • Cyber Security Frameworks and Standards: Overview of Security Governance, Security Awareness and Training, Introduction to Cyber Security Frameworks and Best Practices.
  • Case Studies: Analysis of a major cyber attack and its impact on an organization.
Preserved official unit paragraph

Introduction to Cyber Security: Need, Importance and Challenges of Cyber Security, Cyberspace and Cyber Ecosystem, Information Security vs Cyber Security, Security Goals and Principles, CIA Triad, Cyber Threat Landscape. Security Concepts: Assets, Threats, Vulnerabilities, Exploits, Attack Surface, Security Controls, Security Policies and Procedures. Cyber Security Frameworks and Standards: Overview of Security Governance, Security Awareness and Training, Introduction to Cyber Security Frameworks and Best Practices. Case Studies: Analysis of a major cyber attack and its impact on an organization.

Unit permalink
UNIT II

Cyber Threats, Attacks and Security Controls

9 hours

Derived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.

  • Cyber Threats and Attacks: Malware (Virus, Worm, Trojan Horse, Ransomware, Spyware), Phishing, Social Engineering, Password Attacks, Denial-of-Service (DoS) and Distributed DoS Attacks.
  • Web and System Attacks: SQL Injection, Cross-Site Scripting (XSS), Man-in-the-Middle Attack, Session Hijacking, Insider Threats.
  • Security Controls: Administrative, Technical and Physical Controls, Access Control Mechanisms, Security Monitoring and Logging.
  • Emerging Threats: Cloud Security Threats, Mobile Security Threats, IoT Security Challenges.
  • Case Studies: Investigation of a ransomware attack and mitigation strategies.
Preserved official unit paragraph

Cyber Threats and Attacks: Malware (Virus, Worm, Trojan Horse, Ransomware, Spyware), Phishing, Social Engineering, Password Attacks, Denial-of-Service (DoS) and Distributed DoS Attacks. Web and System Attacks: SQL Injection, Cross-Site Scripting (XSS), Man-in-the-Middle Attack, Session Hijacking, Insider Threats. Security Controls: Administrative, Technical and Physical Controls, Access Control Mechanisms, Security Monitoring and Logging. Emerging Threats: Cloud Security Threats, Mobile Security Threats, IoT Security Challenges. Case Studies: Investigation of a ransomware attack and mitigation strategies.

Unit permalink
UNIT III

Network and Application Security

9 hours

Derived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.

  • Network Security Fundamentals: Network Security Architecture, Secure Network Design, Common Network Vulnerabilities.
  • Network Security Mechanisms: Firewalls, Proxy Servers, Virtual Private Networks (VPNs), Intrusion Detection and Prevention Systems (IDS/IPS), Network Segmentation.
  • Application Security: Secure Software Development Life Cycle (SSDLC), Secure Coding Practices, Vulnerability Assessment and Penetration Testing Concepts.
  • Data Security: Data Classification, Data Protection Techniques, Backup and Recovery Mechanisms.
  • Case Studies: Security assessment of a web application and network infrastructure
Preserved official unit paragraph

Network Security Fundamentals: Network Security Architecture, Secure Network Design, Common Network Vulnerabilities. Network Security Mechanisms: Firewalls, Proxy Servers, Virtual Private Networks (VPNs), Intrusion Detection and Prevention Systems (IDS/IPS), Network Segmentation. Application Security: Secure Software Development Life Cycle (SSDLC), Secure Coding Practices, Vulnerability Assessment and Penetration Testing Concepts. Data Security: Data Classification, Data Protection Techniques, Backup and Recovery Mechanisms. Case Studies: Security assessment of a web application and network infrastructure

Unit permalink
UNIT IV

Cryptography, Authentication and Incident Response

9 hours

Derived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.

  • Cryptography Fundamentals: Principles of Cryptography, Encryption and Decryption, Symmetric and Asymmetric Cryptography.
  • Cryptographic Techniques: Hash Functions, Digital Signatures, Public Key Infrastructure (PKI), Digital Certificates.
  • Authentication and Access Management: Authentication Methods, Multi-Factor Authentication (MFA), Authorization and Identity Management.
  • Incident Response: Security Incident Lifecycle, Detection, Containment, Eradication, Recovery, Incident Reporting and Documentation.
  • Case Studies: Analysis of a security breach and incident response process
Preserved official unit paragraph

Cryptography Fundamentals: Principles of Cryptography, Encryption and Decryption, Symmetric and Asymmetric Cryptography. Cryptographic Techniques: Hash Functions, Digital Signatures, Public Key Infrastructure (PKI), Digital Certificates. Authentication and Access Management: Authentication Methods, Multi-Factor Authentication (MFA), Authorization and Identity Management. Incident Response: Security Incident Lifecycle, Detection, Containment, Eradication, Recovery, Incident Reporting and Documentation. Case Studies: Analysis of a security breach and incident response process

Unit permalink
UNIT V

Cyber Risk Management and Security Governance

9 hours

Derived reading outline. Source text split at semicolons, line breaks and sentence boundaries, not an official topic hierarchy.

  • Cyber Risk Management: Risk Concepts, Risk Identification, Risk Assessment, Risk Analysis, Risk Evaluation and Risk Prioritization.
  • Risk Treatment Strategies: Risk Avoidance, Risk Mitigation, Risk Transfer and Risk Acceptance, Risk Register and Risk Monitoring.
  • Governance and Compliance: Security Governance Principles, Cyber Laws and Regulations, Compliance Requirements, Ethics in Cyber Security.
  • Business Continuity and Disaster Recovery: Business Continuity Planning (BCP), Disaster Recovery Planning (DRP), Backup Strategies, Recovery Objectives and Testing of Recovery Plans.
  • Case Studies: Risk assessment and business continuity planning for an organization
Preserved official unit paragraph

Cyber Risk Management: Risk Concepts, Risk Identification, Risk Assessment, Risk Analysis, Risk Evaluation and Risk Prioritization. Risk Treatment Strategies: Risk Avoidance, Risk Mitigation, Risk Transfer and Risk Acceptance, Risk Register and Risk Monitoring. Governance and Compliance: Security Governance Principles, Cyber Laws and Regulations, Compliance Requirements, Ethics in Cyber Security. Business Continuity and Disaster Recovery: Business Continuity Planning (BCP), Disaster Recovery Planning (DRP), Backup Strategies, Recovery Objectives and Testing of Recovery Plans. Case Studies: Risk assessment and business continuity planning for an organization

Unit permalink

Marks and credits

HeadMarksCredit
CCE (continuous comprehensive evaluation)303
End-semester exam70

Prerequisite: Computer Networks, Operating System.

Course outcomes

  1. CO1To explain the fundamental concepts of cybersecurity, information security principles, threats, vulnerabilities, and security controls.
  2. CO2To analyze various cyber threats, attacks, and vulnerabilities and recommend suitable protection mechanisms.
  3. CO3To apply network security, application security, cryptographic techniques, and authentication mechanisms to enhance system security.
  4. CO4To perform basic security assessment activities and implement appropriate incident response procedures for security incidents.
  5. CO5To evaluate cybersecurity risks and apply governance, compliance, business continuity, and disaster recovery strategies to improve organizational resilience.

Books

Text books

Reference books

FAQ

How many units are in Cyber Security & Risk Management?

Cyber Security & Risk Management (PEC-362D-IT) has 5 units and 45 hours of theory: Unit I Introduction To Cyber Security And Security Principles (9 h); Unit II Cyber Threats, Attacks and Security Controls (9 h); Unit III Network and Application Security (9 h); Unit IV Cryptography, Authentication and Incident Response (9 h); Unit V Cyber Risk Management and Security Governance (9 h).

What is the marks scheme for Cyber Security & Risk Management?

The official Information Technology 2024 pattern syllabus lists continuous comprehensive evaluation (CCE) for 30 marks and the end-semester exam for 70 marks, for 3 credits.

What should I know before Cyber Security & Risk Management?

Prerequisite listed in the syllabus: Computer Networks, Operating System.

Add to my plan

Browse all syllabus courses