COMP47900 Cyber Risk Assessment and Standards

Academic Year 2023/2024

This module will enable students to understand each of the key steps of a risk assessment, including how to identify risks, manage hazards and determine the likelihood of harm using a standards-based approach that covers both ISO and NIST standards. Students will be able to carry out a risk assessment of an organisation of their choice as a group project. The module will cover the theories, concepts, and practices of threat modeling and enterprise risk management. It will outline the context for risk management, the various methods of risk assessment and the options for risk response and mitigation.

Show/hide contentOpenClose All

Curricular information is subject to change

Learning Outcomes:

- Understand the concepts of risk, risk response and mitigation
- Identify and protecting an organization from unacceptable losses
- Apply the NIST/ISO risk management processes
- Outlining the system security boundary
- Create a system security plan
- Identify security risk components
- Estimate the impact of compromises to confidentiality, integrity and availability
- Adopt the appropriate model for categorizing system risk
- Setting the stage for successful risk management
- Documenting risk assessment and management decisions

Indicative Module Content:

- Introduction to risk, risk management, risk mitigation
- System Security Plans (SSPs)
- Controls
- Risk and the system security boundary
- Identifying security risk components
- NIST/ISO risk management processes
- Risk impact: compromises to confidentiality, integrity and availability
- Models for categorizing system risk
- Documenting critical risk assessment and management
- Collecting on-going security metrics

Student Effort Hours: 
Student Effort Type Hours
Lectures

24

Practical

6

Autonomous Student Learning

82

Total

112

Approaches to Teaching and Learning:
The module will be delivered via online lecture and 3 in-person workshops/practicals. 
Requirements, Exclusions and Recommendations

Not applicable to this module.


Module Requisites and Incompatibles
Not applicable to this module.
 
Assessment Strategy  
Description Timing Open Book Exam Component Scale Must Pass Component % of Final Grade
Examination: End-of-term examination 2 hour End of Trimester Exam No Graded No

40

Continuous Assessment: Learning Journal Throughout the Trimester n/a Graded No

35

Group Project: Group work on risk assessment research, conducting a risk assessment and creating a system security plan. Throughout the Trimester n/a Graded No

25


Carry forward of passed components
Yes
 
Resit In Terminal Exam
Summer Yes - 2 Hour
Please see Student Jargon Buster for more information about remediation types and timing. 
Feedback Strategy/Strategies

• Feedback individually to students, post-assessment

How will my Feedback be Delivered?

The lecturer will provide either written or oral feedback to the students

Timetabling information is displayed only for guidance purposes, relates to the current Academic Year only and is subject to change.
 
Autumn
     
Practical Offering 1 Week(s) - 0, 7, 13 Fri 14:00 - 15:50