Security Risk Management Principles
Security Risk Management Principles
Course Learning Rationale (CLR): The purpose of learning this course is to: Program Outcomes (PO) Program
Specific
CLR-1: understand the fundamental knowledge about Security Risk 1 2 3 4 5 6 7 8 9 10 11 12 Outcomes
CLR-2: understand the various analysis on Security Risk Management
Design/development of
Communication
CLR-4: understand the IT audit and its activities
Environment &
Sustainability
CLR-5: understand the techniques for implementing security in audit
solutions
society
PSO-1
PSO-2
PSO-3
Ethics
Course Outcomes (CO): At the end of this course, learners will be able to:
CO-1: acquire the knowledge on the fundamentals of Risk management - 3 - - - - - - - - - 2 - - -
CO-2: acquire the ability to apply various techniques for data collection - - - - - - - - - - - 2 - - -
CO-3: utilize the principles of data analysis - 3 - - - - - - - - - - - - 3
CO-4: acquire the ability to apply IS audit - 3 - - - - - - - - - 2 - - 3
CO-5: apply the knowledge gained on auditing methodologies - 3 - - - - - - - - - - - - 3
246
B.Tech / M.Tech (Integrated) Programmes-Regulations 2021-Volume-11-CSE-Higher Semester Syllabi-Control Copy
Unit-5 - Information Security Audit Analysis 9 Hour
Detailing Information Security Audit, Purpose of IS Audit, Expectation from IS Auditor, Steps to Conduct IS Audit, Classification of Audit, Traditional Audit, Difference Between Audit and Assessment, Relationship
Between Auditor, Auditee and Client; Their Duties, SLA Introduction, SLA Components, Auditing Firm Organizational Chart, Auditing Firm functionalities, Policy Vs Procedures Standard Vs Guideline, Basic Types
of Measurement Metrics, Members of Auditing Committee, Skills Matrix, Example, Audit Evidence, Examples, Direct and Indirect Evidence.
Learning 1. Evan Wheeler, “Security Risk Management”, Syngress ISBN: 97815, 2011 3. David L. Cannon, “CISA Certified Information Systems Auditor Study Guide”, John Wiley & Sons,
Resources 2. Bruce Newsome, “A Practical Introduction to Security and Risk Management”, 2013 ISBN: 978-0-470-23152-4, 2009.
Learning Assessment
Continuous Learning Assessment (CLA)
Summative
Formative Life-Long Learning
Bloom’s Final Examination
CLA-1 Average of unit test CLA-2
Level of Thinking (40% weightage)
(50%) (10%)
Theory Practice Theory Practice Theory Practice
Level 1 Remember 15% - 15% - 15% -
Level 2 Understand 25% - 20% - 25% -
Level 3 Apply 30% - 25% - 30% -
Level 4 Analyze 30% - 25% - 30% -
Level 5 Evaluate - - 10% - - -
Level 6 Create - - 5% - - -
Total 100 % 100 % 100 %
Course Designers
Experts from Industry Experts from Higher Technical Institutions Internal Experts
1. Mr.Arun.A, SRMIST
247
B.Tech / M.Tech (Integrated) Programmes-Regulations 2021-Volume-11-CSE-Higher Semester Syllabi-Control Copy