Course detail

Management Information Security

FP-ImibeKAcad. year: 2022/2023

Information Security Management is focused on the security aspects of information systems and to explore the basic elements of creating security policies of the organization. It is to introduce students to the main areas and directions of the implementation of security measures and to acquaint them with their policies.

Language of instruction

Czech

Number of ECTS credits

3

Mode of study

Not applicable.

Learning outcomes of the course unit

Emphasis is also placed on gaining knowledge of current methodologies of information security management in enterprise IS, especially according to the ČSN ISO/IEC 27001 standard.

Prerequisites

Knowledge of information systems, computer networks, operating systems and basic programming.

Co-requisites

Not applicable.

Planned learning activities and teaching methods

The course contains lectures that explain basic principles, problems and methodology of the discipline, and exercises that promote the practical knowledge of the subject presented in the lectures.

Assesment methods and criteria linked to learning outcomes

It will be specified by teacher.

Course curriculum

1. Digital literacy.
2. Basic terminology of ISMS.
3. Definition of ISMS.
4. Implementation methodology of ISMS.
5. Risk analysis.
6. Security controls.
7.Security standards and norms.
8. Network security management.
9. Application security management.
10. Information security for supplier relationships.
11. Data security management.
12. Personaly security issues.
13. Legal aspects of cyber security. Cyber Security Act and implementing regulations.

Work placements

Not applicable.

Aims

The aim of the course is to introduce students to the main principles of the Information Security Management System (ISMS) and directions in the implementation of security measures and to familiarize them with their individual areas.

Specification of controlled education, way of implementation and compensation for absences

It will be specified by teacher.

Recommended optional programme components

Not applicable.

Prerequisites and corequisites

Not applicable.

Basic literature

SMEJKAL, V., SOKOL, T. a J. KODL. Bezpečnost informačních systémů podle zákona o kybernetické bezpečnosti. Plzeň: Nakladavatelství Aleš Čeněk, 2019. 377 s. ISBN 978-80-7380-765-8. (CS)
Smejkal, V., Rais, K. Řízení rizik ve firmách a jiných organizacích. 4., aktualizované a rozšířené vydání. Praha: GRADA, 2013, 488 str., ISBN 978-80-247-4644-9 (CS)
ČSN ISO/IEC 27000:2017 Informační technologie – Bezpečnostní techniky – Systémy řízení bezpečnosti informací – Přehled a slovník (CS)
DOUCEK, P., NOVÁK, L., NEDOMOVÁ, L., SVATÁ, V. Řízení bezpečnosti informací. 2. vyd. Praha: Professional Publishing, 2011. (CS)
ČSN ISO/IEC 27001:2014 Informační technologie – Bezpečnostní techniky – Systémy řízení bezpečnosti informací – Požadavky (CS)
ČSN ISO/IEC 27002:2014 Informační technologie – Bezpečnostní techniky – Systémy řízení bezpečnosti informací – Soubor postupů pro opatření bezpečnosti informací (CS)
ČSN ISO/IEC 27004:2018 Informační technologie – Bezpečnostní techniky – Systémy řízení bezpečnosti informací – Monitorování, měření, analýza a hodnocení (CS)
ČSN ISO/IEC 27003:2018 Informační technologie – Bezpečnostní techniky – Systémy řízení bezpečnosti informací – Pokyny (CS)
Národní úřad pro kybernetickou a informační bezpečnost. MINIMÁLNÍ BEZPEČNOSTNÍ STANDARD pro subjekty, které nespadají pod zákon o kybernetické bezpečnosti. Verze 1.0, platná ke dni 17. července 2020. Dostupné na: https://nukib.cz/cs/infoservis/dokumenty-a-publikace/podpurne-materialy/ (CS)

Recommended reading

SMEJKAL, V. Kybernetická kriminalita. 2. vydání. Plzeň: Nakladatelství Aleš Čeněk, 2018. 936 str., ISBN 978-80-7380-720-7. (CS)
ONDRÁK, V., SEDLÁK, P., MAZÁLEK, V. Problematika ISMS v manažerské informatice. Brno: CERM, 2013. (CS)
Časopis DSM - Data Security Management. Vyd. Tate International, Praha.

Classification of course in study plans

  • Programme MGR-IM-KS Master's, 1. year of study, winter semester, compulsory

Type of course unit

 

Guided consultation in combined form of studies

12 hours, optionally

Teacher / Lecturer

Syllabus

The aim of the course is a basic understanding of information security management (ISMS) in the complex concept of organizational management.
A follow-up objective is to understand the linkages in security issues from the individual to the organization.
Another objective is to introduce students to the main areas and directions in the implementation of security measures and to familiarize them with their principles.
1. Digital literacy
2. Basic concepts of information security management
3. Definition of information security management
4. Methodology of ISMS implementation
5. Security risk analysis
6. Security measures
7. Security standards
8. Network security management
9. Application security management
10. Supply chain security
11. Data protection management
12. Personal security and physical IT security issues.
13. Legal aspects of cyber security. Cybersecurity Act and implementing regulations.