MIS 324-001 Information Security Management

COVID-19 Statement

Following CDC Guidelines, UNC System directives, and out of mutual respect as outlined in the UNCW Seahawk Respect Compact, all faculty, staff, and students will wear face coverings while inside buildings. Students who are unprepared or unwilling to wear protective face coverings will not be permitted to participate in face-to-face sessions and will need to leave the building. Noncompliant students will be referred to the Dean of Students for a Code of Student Conduct violation. Any student who has a medical concern with wearing a face covering should contact the Disability Resource Center at (910) 962-7555.

Syllabus - Spring 2021

Course Description

Prerequisite: (CIT 110 or MIS 213) and CIT 225.
Current standards of due care and best business practices in Information Security. Includes examination of security technologies, methodologies, and practices. Focus is on evaluation and selection of optimal security posture. Topics include evaluation of security models, risk assessment, threat analysis, organizational technology evaluation, security implementation, disaster recovery planning and security policy formulation and implementation.

Course Delivery

This course is being delivered as AFAO
AFAO = "Some students are assigned to attend an in-person class on a specific day of the week while other students in the course attend the class on other delivery days each week. The remaining course content is delivered via asynchronous online methods."
Students will receive an email indicating which day of the week they may attend class in person.

Schedule

Monday Topic Wednesday Topic
18 January No class 20 January Introduction/Course Mechanics
Read Unit 1: Introduction to Security
TQ: Pre-Course Assessment [due 22Jan@2359]
TQ: Security+ Exam Objectives/Course Notes [due 22Jan@2359]
TQ: Project 1-2 Quiz [due 22Jan@2359]
HO: Lab Simulation 1-1 [due 24Jan@2359]
HO: Lab Simulation 1-2 [due 24Jan@2359]
HO: Projects 1-4, 1-5, and 1-3 [due 24Jan@2359]
HO: Lab 1-1 [due 24Jan@2359]
TQ: Unit 1 Quiz [due 24Jan@2359]
25 January Read Unit 2: Malware and Social Engineering Attacks
TQ: Unit 2 Vocabulary Quiz [due 27Jan@2359]
HO: Case Project 2-4 [due 29Jan@2359]

Office of Student Professional Development
27 January HO: Lab Simulation 2-1 [due 31Jan@2359]
TQ: Unit 2 Quiz [due 31Jan@2359]
HO: Capstone Introduction
HO: Social Engineering Recon [due 31Jan@2359]
1 February Read Unit 3: Basic Cryptography
TQ: Unit 3 Vocabulary Quiz [due 3Feb@2359]
TQ: Hashing [due 5Feb@2359]
3 February HO: Lab Simulation 3-1 [due 7Feb@2359]
HO: Lab 3-1 [due 7Feb@2359]
TQ: Unit 3 Quiz [due 7Feb@2359]
8 February Read Unit 4: Advanced Cryptography and PKI
TQ: Unit 4 Vocabulary Quiz [due 10Feb@2359]
HO: Lab Simulation 4-1 [due 12Feb@2359]
10 February HO: Lab 4-1 [due 14Feb@2359]
TQ: Unit 4 Quiz [due 14Feb@2359]
HO: Data Encryption [due 14Feb@2359]
15 February Read Unit 5: Networking and Server Attacks
TQ: Unit 5 Vocabulary Quiz [due 17Feb@2359]
HO: Lab Simulation 5-1 [due 19Feb@2359]
17 February HO: Lab 5-1 [due 21Feb@2359]
TQ: Unit 5 Quiz [due 21Feb@2359]
22 February Read Unit 6: Network Security Devices, Design, and Technology
TQ: Unit 6 Vocabulary Quiz [due 24Feb@2359]
HO: Lab Simulation 6-1 [due 26Feb@2359]
24 February HO: Lab 6-1 [due 28Feb@2359]
HO: Lab 6-2 [due 28Feb@2359]
HO: Firewall (short) [due 28Feb@2359]
TQ: Unit 6 Quiz [due 28Feb@2359]
1 March Read Unit 7: Administering a Secure Network
TQ: Unit 7 Vocabulary Quiz [due 3Mar@2359]
HO: Lab Simulation 7-1 [due 5Mar@2359]
3 March HO: Lab 7-1 [due 7Mar@2359]
HO: Lab 7-2 [due 7Mar@2359]
TQ: Unit 7 Quiz [due 7Mar@2359]
8 March Read Unit 8: Wireless Network Security
TQ: Unit 8 Vocabulary Quiz [due 10Mar@2359]
HO: Lab Simulation 8-1 [due 12Mar@2359]
10 March HO: Lab 8-1 [due 14Mar@2359]
TQ: Unit 8 Quiz [due 14Mar@2359]
HO: Scanning with OpenVAS [due 14Mar@2359]
15 March Read Unit 9: Client and Application Security
TQ: Unit 9 Vocabulary Quiz [due 17Mar@2359]
HO: Lab Simulation 9-1 [due 19Mar@2359]
17 March HO: Lab 9-1 [due 21Mar@2359]
TQ: Unit 9 Quiz [due 21Mar@2359]
22 March Read Unit 10: Mobile and Embedded Device Security
TQ: Unit 10 Vocabulary Quiz [due 24Mar@2359]
HO: Lab Simulation 10-1 [due 26Mar@2359]
24 March Business Week Speaker
HO: Lab 10-1 [due 28Mar@2359]
TQ: Unit 10 Quiz [due 28Mar@2359]
HO: Implement Patching using WSUS [due 28Mar@2359]
29 March Read Unit 11: Authentication and Account Management
TQ: Unit 11 Vocabulary Quiz [due 31Mar@2359]
HO: Lab Simulation 11-1 [due 2Apr@2359]
31 March HO: Lab 11-1 [due 4Apr@2359]
TQ: Unit 11 Quiz [due 4Apr@2359]
5 April Read Unit 12: Access Management
TQ: Unit 12 Vocabulary Quiz [due 7Apr@2359]
HO: Lab Simulation 12-1 [due 9Apr@2359]
7 April HO: Lab Simulation 12-2 [due 11Apr@2359]
HO: Lab 12-1 [due 11Apr@2359]
TQ: Unit 12 Quiz [due 11Apr@2359]
HO: Password Cracking Tools [due 11Apr@2359]
12 April Read Unit 13: Vulnerability Assessment and Data Security
TQ: Unit 13 Vocabulary Quiz [due 14Apr@2359]
HO: Lab Simulation 13-1 [due 16Apr@2359]
14 April HO: Lab Simulation 13-2 [due 18Apr@2359]
HO: Lab 13-1 [due 18Apr@2359]
TQ: Unit 13 Quiz [due 18Apr@2359]
19 April Read Unit 14: Business Continuity
TQ: Unit 14 Vocabulary Quiz [due 21Apr@2359]
HO: Lab Simulation 14-1 [due 23Apr@2359]
21 April HO: Lab Simulation 14-2 [due 25Apr@2359]
HO: Lab 14-1 [due 25Apr@2359]
HO: Lab 14-2 [due 25Apr@2359]
TQ: Unit 14 Quiz [due 25Apr@2359]
26 April Read Unit 15: Risk Mitigation
TQ: Unit 15 Vocabulary Quiz [due 28Apr@2359]
TQ: Unit 15 Quiz [due 28Apr@2359]
TQ: Post Assessment [due 28Apr@2359]
28 April HO: Lab Simulation 15-1
HO: Lab 15-1
HO: Backup and Recovery
3 May No class 5 May Final Exam (1130-1430)

TQ = Take Quiz; HO Hands-on

Course Student Learning Outcomes (SLOs)

  1. Describe the key concepts in network defense (defense in depth, minimizing exposure, etc.).
  2. Explain how network defense tools (firewalls, IDS, etc.) are used to defend against attacks and mitigate vulnerabilities.
  3. Analyze how security policies are implemented on systems to protect a network.
  4. Evaluate how network operational procedures relate to network security.
  5. Analyze problems, recommend solutions, products, and technologies to meet business objectives.
  6. Recommend best security practices to achieve stated business objectives based on risk assumptions.
  7. Actively protect information technology assets and infrastructure from external and internal threats.
  8. Monitor systems for anomalies, proper updating, and patching.
  9. Assist in incident responses for any breaches, intrusions, or theft.
  10. Evaluate and perform planning, testing, and implementation of software and hardware deployed.
  11. Examine a specific architecture and identify potential vulnerabilities.
  12. Design a secure architecture for a given application.

Policy Information

Academic Honor Code

As a student at The University of North Carolina Wilmington, I am committed to honesty and truthfulness in academic inquiry and in the pursuit of knowledge. I pledge to uphold and promote the UNCW Student Academic Honor Code.

The University of North Carolina Wilmington is a community of high academic standards where academic integrity is valued. UNCW students are committed to honesty and truthfulness in academic inquiry and in the pursuit of knowledge. This commitment begins when new students matriculate at UNCW, continues as they create work of the highest quality while part of the university community, and endures as a core value throughout their lives.

Please read and be familiar with the UNCW Student Academic Honor Code. I have highlighted some parts that are particularly relevant to thsi course here.

Academic dishonesty in any form will not be tolerated in this class.

Grading

Grading Scale (+/- at instructor discretion)

A: (avg >= 90)
B: (90 > avg) and (avg >= 80)
C: (80 > avg) and (avg >= 70)
D: (70 > avg) and (avg >= 60)

Coursework Weighting

10% Quizzes
40% Assignments
30% Tests
20% Final

Late Policy

An assignment submitted after the due time/date will not generally be graded and will receive zero (0) points. It does not matter if it is 20 minutes late or 2 weeks late.

There are two exceptions to this policy:

  1. Unexpected life event that derails a reasonable plan to accomplish an assignment by the due time/date; e.g. car accident, illness, family death, etc. Email me if/when this occurs and I will be reasonable.
  2. Token. Each of you has one (1) virtual excuse token that you can use to have a late assignment graded without having to provide a reason. Simply email me and say that you would like to use a token to receive a grade on a late assignment. NOTE: If your token is *not* used during the semester, it is worth 1 point on your final average. E.g., you have an 89.1% final average, but have submitted all assignments on time - your token will be applied to your final average which will become 90.1%. Because of this policy, there will be no rounding at semester's end. If you have an 89.6%, but used your token during the semester your grade will not be rounded to a 90% - this is because you have already benefited from the token by not receiving a zero on the late assignment.

Extra Credit

There is no specified extra credit in this class. I will, on occasion, subjectively award extra credit for assignment solutions that demonstrate meaningful, functional effort beyond the norm.

Attendance

I will offer opportunities to meet both in class and on Zoom. If you think it is to your benefit to attend, please do so. Otherwise, you will not be penalized for non-attendance.

Communication

The best way to contact me is via email. When writing me email, please, indicate your class AND section number. Also, be clear/concise: start with your question and then provide supporting details. You do not need to tell me how hard you have been working or how confused you are. Example
If you post questions in the assignment comment section in Canvas, I will likely not see it - don't do that.

Student Illness

Students are to do a health check each day before coming to campus. Students who experience COVID-19 symptoms should immediately contact the Abrons Student Health Center at (910) 962-3280. If a student becomes ill, s/he should let the professor know and must not attend the course in-person. If a student is too ill to attend virtually, they will be given the opportunity to complete the material asynchronously.

Disaster Contingency Plan

In the event that UNCW closes, students will be given an assignment to make up for 1 week of missed class time. This will be emailed to students within two days of the UNCW closing announcement. In the event that the rest of the semester is online, students need to be prepared by having reliable internet access, a webcam, and a microphone.

Students with Disabilities

If you are a student with a disability and need accommodations, you must be registered with Disability Services (DePaolo Hall, 910.962.7555). Please provide your Accommodations Letter within the first week of class or as soon as possible. You should then meet with your instructor to make mutually agreed upon arrangements based upon the recommendations in the Accommodations Letter. For additional information, please see UNCW Disability.

Title IX

UNCW takes all forms of interpersonal violence very seriously. When students disclose, first- or third-hand, to faculty or staff about sexual misconduct, domestic violence, dating violence and/or stalking, this information must be reported to the administration in order to ensure that students' rights are protected, appropriate resources are offered, and the need for further investigation is explored to maintain campus safety. There are three confidential resources who do not need to report interpersonal violence: UNCW CARE, the Student Health Center, and the Counseling Center. If you want to speak to someone in confidence, these resources are available, including CARE's 24-hour crisis line (910-512-4821). For more information, please visit www.uncw.edu/care

Code of Student Conduct

This course is subject to the Code of Student Life of the University of North Carolina Wilmington (the Code). The full Code is found here Code of Student Life. UNCW practices zero tolerance for violence and harassment of any kind. For emergencies, contact UNCW CARE at 910.962.2273 or Campus Police at 910.962.3184. For University or community resources visit Safe Relate Campus Resources.

Religious Observance Policy

In accordance with NC SL 2010-211, students are entitled to two excused absences for religious observances per academic year. These absences must be requested using the form provided on SeaNet, under "Student Services." These requests must be submitted by the student prior to the absence. Once the request is submitted, an email will be sent to all impacted instructors automatically. There is no need to send additional notification to instructors or the Registrar's Office. Any absence for religious purposes will be considered unexcused unless the appropriate form is submitted.

Seahawk Respect Compact

In the pursuit of excellence, UNC Wilmington actively fosters, encourages, and promotes inclusiveness, mutual respect, acceptance, and open-mindedness among students, faculty, staff and the broader community.

Therefore, we expect members of the campus community to honor these principles as fundamental to our ongoing efforts to increase access to and inclusion in a community that nurtures learning and growth for all.