COP4456 BGA- Information SecurityBahçeşehir UniversityDegree Programs MEDICINEGeneral Information For StudentsDiploma SupplementErasmus Policy StatementNational QualificationsBologna Commission
MEDICINE
Bachelor TR-NQF-HE: Level 6 QF-EHEA: First Cycle EQF-LLL: Level 6

Course Introduction and Application Information

Course Code Course Name Semester Theoretical Practical Credit ECTS
COP4456 BGA- Information Security Fall 3 0 3 6
This catalog is for information purposes. Course status is determined by the relevant department at the beginning of semester.

Basic information

Language of instruction: English
Type of course: Non-Departmental Elective
Course Level: Bachelor’s Degree (First Cycle)
Mode of Delivery: Face to face
Course Coordinator : Dr. Öğr. Üyesi GÖRKEM KAR
Course Objectives: This course is designed to teach students how to engage all functional levels within the enterprise to deliver information system security. To this end, the course addresses a range of topics, each of which is vital to securing the modern enterprise.
These topics include inter alia plans and policies, enterprise roles, security metrics, risk management, standards and regulations, physical security, and business continuity.
Each piece of the puzzle must be in place for the enterprise to achieve its security goals; adversaries will invariably find and exploit weak links.

Learning Outcomes

The students who have succeeded in this course;
1) Assess the current security landscape, including the nature of the threat, the general status of common vulnerabilities, and the likely consequences of security failures
2) Critique and assess the strengths and weaknesses of general cybersecurity models, including the CIA triad
3) Appraise the interrelationships among elements that comprise a modern security system, including hardware, software, policies, and people
4) Assess how all domains of security interact to achieve effective system-wide security at the enterprise level.
5) Compare the interrelationships among security roles and responsibilities in a modern information-driven enterprise—to include interrelationships across security domains (IT, physical, classification, personnel, and so on)
6) Assess the role of strategy and policy in determining the success of information security;
7) Estimate the possible consequences of misaligning enterprise strategy, security policy, and security plans,
8) Assess the role of good metrics and key performance indicators (KPIs) in security assessment and governance,
9) Create a good set of information security metrics
10) Evaluate the trends and patterns that will determine the future state of cybersecurity.

Course Content

The Security Environment ,Principles of Cybersecurity,Cybersecurity Management Concepts, Cybersecurity Management Concepts, Enterprise Roles and Structures, Strategy and Strategic Planning, Security Plans and Policies, Security Standards and Controls, Risk Management, Security Metrics and Key Performance Indicators (KPIs), Security Education Awareness, Training, Physical Security and Environmental Events, Contingency Planning , Security Education, Training, and Awarenes, The future of cybersecurity

Weekly Detailed Course Contents

Week Subject Related Preparation
1) The Security Environment Threats, vulnerabilities, and consequences Advanced persistent threats The state of security today Why security matters to TSE
2) "Principles of Cybersecurity • Cybersecurity models (the CIA triad, the star model, the Parkerian hexad) • Variations on a theme: computer security, information security, and information assurance "
3) "Cybersecurity Management Concepts: Security governance Management models, roles, and functions
4) " Enterprise Roles and Structures: Information security roles and positions Alternative enterprise structures and interfaces
5) " Strategy and Strategic Planning: • Strategy • Strategic planning and security strategy • The information security lifecycle • Architecting the enterprise "
6) " Security Plans and Policies: • Levels of planning • Planning misalignment • The System Security Plan (SSP) • Policy development and implementation
7) "Security Standards and Controls: • Security standards and controls • Certification and accreditation (C&A)
8) " Risk Management : • Principles of risk • Types of risk • Risk strategies • The Risk Management Framework (RMF)
9) " Security Metrics and Key Performance Indicators (KPIs) : • The challenge of security metrics • What makes a good metric • Approaches to security metrics • Metrics and FISMA "
10) " Security Education Awareness, Training: • Human factors in security • Developing and implementing a security training plan • Cross-domain training (IT and other security domains)
11) " Physical Security and Environmental Events : • Physical and environmental threats • Physical and environmental controls
12) " Contingency Planning Developing a contingency plan • Understanding the different types of contingency plan • Responding to events "
13) "Security Education, Training, and Awarenes • Human factors in security • Developing and implementing a security training plan • Cross-domain training (IT and other security domains)
14) "The future of cybersecurity • Key future uncertainties • Possible future scenarios • How to apply what you’ve learned

Sources

Course Notes / Textbooks: Information Security: Principles and Practice - Jon Erickson
References:

Evaluation System

Semester Requirements Number of Activities Level of Contribution
Quizzes 2 % 10
Homework Assignments 3 % 15
Project 1 % 15
Midterms 1 % 20
Final 1 % 40
Total % 100
PERCENTAGE OF SEMESTER WORK % 45
PERCENTAGE OF FINAL WORK % 55
Total % 100

ECTS / Workload Table

Activities Number of Activities Duration (Hours) Workload
Course Hours 14 3 42
Study Hours Out of Class 14 3 42
Homework Assignments 3 7 21
Midterms 1 15 15
Final 1 25 25
Total Workload 145

Contribution of Learning Outcomes to Programme Outcomes

No Effect 1 Lowest 2 Low 3 Average 4 High 5 Highest
           
Program Outcomes Level of Contribution
1) Integrates the knowledge, skills and attitudes acquired from basic and clinical medical sciences, behavioral sciences and social sciences, and uses them in health service delivery.
2) In patient management, shows a biopsychosocial approach that takes into account the socio-demographic and sociocultural background of the individual, regardless of language, religion, race and gender.
3) In the provision of health services, prioritizes the protection and development of the health of individuals and society.
4) Taking into account the individual, societal, social and environmental factors affecting health; does the necessary work to maintain and improve the state of health.
5) By recognizing the characteristics, needs and expectations of the target audience, provides health education to healthy/sick individuals and their relatives and other healthcare professionals.
6) Shows a safe, rational and effective approach in health service delivery, prevention, diagnosis, treatment, follow-up and rehabilitation processes.
7) Performs invasive and/or non-invasive procedures in diagnosis, treatment, follow-up and rehabilitation processes in a safe and effective way for the patient.
8) Provides health services by considering patient and employee health and safety.
9) In the provision of health services, takes into account the changes in the physical and socioeconomic environment on a regional and global scale, as well as the changes in the individual characteristics and behaviors of the people who apply to it.
10) Takes good medical practice into account while carrying out his/her profession.
11) Fulfills its duties and obligations within the framework of ethical principles, rights and legal responsibilities required by its profession.
12) Demonstrates decisive behavior in providing high-quality health care, taking into account the integrity of the patient.
13) Evaluates his/her performance in his/her professional practice by considering his/her emotions and cognitive characteristics.
14) Advocates improving the provision of health services by considering the concepts of social reliability and social responsibility for the protection and development of public health.
15) Can plan and carry out service delivery, training and consultancy processes related to individual and community health in cooperation with all components for the protection and development of health.
16) Evaluates the impact of health policies and practices on individual and community health indicators and advocates increasing the quality of health services.
17) The physician attaches importance to the protection of his/her own physical, mental and social health, and does what is necessary for this
18) Shows exemplary behavior and leads the healthcare team during service delivery.
19) Uses resources cost-effectively, for the benefit of society and in accordance with the legislation, in the planning, implementation and evaluation processes of health services in the health institution he/she is the manager of.
20) Establishes positive communication within the health team it serves and assumes different team roles when necessary.
21) Is aware of the duties and responsibilities of the health workers in the health team and acts accordingly.
22) In the professional practices, works in harmony and effectively with the colleagues and other professional groups.
23) Communicates effectively with patients, their relatives, healthcare professionals, other professional groups, institutions and organizations.
24) Communicates effectively with individuals and groups that require a special approach and have different socio-cultural characteristics.
25) In the diagnosis, treatment, follow-up and rehabilitation processes, shows a patient-centered approach that associates the patient with the decision-making mechanisms.
26) Plans and implements scientific research, when necessary, for the population it serves, and uses the results and/or the results of other research for the benefit of the society.
27) Reaches and critically evaluates current literature knowledge about his/her profession.
28) Applies the principles of evidence-based medicine in clinical decision making.
29) Uses information technologies to increase the effectiveness of its work on health care, research and education.
30) Effectively manages individual work processes and career development.
31) Demonstrates skills in acquiring and evaluating new knowledge, integrating it with existing knowledge, applying it to professional situations and adapting to changing conditions throughout professional life.
32) Selects the right learning resources to improve the quality of the health service it offers, organizes its own learning process