Swinburne University of Technology - Melbourne Australia
Future Students - Courses
Duration
Contact Hours
Campus
Prerequisite
Corequisite
1 Semester or equivalent
36 Hours
Hawthorn
HIT5401 Introduction to Business Information Systems or HIT8036 Business Information Systems for a Rapidly Changing World or HIT8424 Information Systems Management
Nil
Credit Points: 12.5 Credit Points
A unit of study in the Master of Information Technology, Master of Information Technology Project Management , Master of Information Technology (Professional Computing) and Master of Technology (Information Technology).
This unit of study aims to provide an understanding of the major information risk and security management issues facing managers in the effective use of information technology in contemporary organisations.Learning OutcomesStudents who complete this unit of study should be able to: Describe the importance of identifying and managing IS-related risk and security issues in organisations, and the relationship between these and the achievement of business value from IS/IT investmentsRecognise the costs of not appropriately identifying and managing risk and security concerns in projects and organisations, resulting in IS/IT failures, dysfunctional systems, and systems which fail to deliver value to key stakeholdersDevelop and document IS/IT risk and security management plans that detail contingency planning strategies and practicesExplain the major theories and concepts associated with IS failure and the management of IS risk, including factors argued to lead to unsatisfactory outcomes with respect to IS/IT.Explain failures and risks associated with Information SecurityConduct comprehensive risk assessments of IS/ IT relater projects and practicesRecognise the relevance of human factors (culture & politics) and organisational factors (complexity, rate of change, etc) to IS risk identification and security managementAdopt a critical approach to IS risk and security management and make recommendations based on sound theory and practice.
Lecture (24 hrs), Tutorial/Seminar (12 hrs)
Assignments, Examination
Students will be provided with feedback on progress in attaining the following generic skills:• teamwork skills,• analysis skills,• problem solving skills,• communications skills,• ability to tackle unfamiliar problems• ability to work independently
Risk Assessment theory and conceptsRisk mitigation theory and conceptsInformation security governance (role of senior management in information security)Developing information security strategyInformation security organisationManaging information security programmesRole of policies and standards in IS risk and security managementContingency planning including business continuity and disaster recovery planningIncident managementLaws, regulations and ethics in context of information securityCompliance with information risk and security requirementsThe major theories and concepts associated with IS failure and the management of IS risk and security issuesHuman factors (culture & politics) and organisational factors (complexity, rate of change, etc) to risk identification and management
Tipton, H.F., Information Security management Handbook, 6th Ed Taylor & Francis, 2008Peltier, TR, Information Security Risk Analysis, 2nd edn, Auerbach Publications, 2005.Jordan, E & Silcock, L, Beating IT Risks, Chichester, Wiley, 2006.Alberts, C & Dorofee, A, Managing Information Security Risks. Boston, Addison Wesley, 2003. Glass, RL, Software Runaways: Lessons Learned form Massive Software Project Failures. Upper Saddle River, N.J., Prentice Hall, 1998. Slay, J & Koronios, A, IT Security & Risk Management, John Wiley & Sons, 2006.Dark, M., Information Assurance and Security Ethics in Complex Systems: Interdisciplinary Perspectives, Information Science PublishingFragniere, E., Sullivan, G., 2007, Risk Management, Safeguarding Company Assets, Axzo PressGene, K., Love, P., Spafford, G., 2008, Visible Ops Security, ITPIMerkov, M., Breithaupt, J., 2006, Information Security Principles and Practices, Prentice HallRaggad, B., 2010, Information Security Management: Concept and Practice, CRC Press Whitman, M., Mattord, H., 2010, Management of Information Security, 3rd edn,Cengage Learning, AURelevant international and Australian standards