Learning Objectives
At the end of this course, students will be able to:
- Formally define: threat, vulnerability, and risk analysis.
- Differentiate between quantitative and qualitative RA methodologies.
- Identify and prioritize informational assets. Conduct an Information Criticality Analysis.
- Perform a Business Impact Analysis.
- Conduct formal vulnerability, threat, and risk analyses.
- Perform Network Signature Analysis.
- Make more informed information systems security policy and procedural evaluations.
- Based upon a strategic process, develop appropriate information security policies.
- Design a security education, training and awareness program.
- Research/report the current information systems security regulatory and legal environment.
- Distinguish legal issues in information systems security that can be analyzed by a computer security professional from those that require an attorney.
- Conduct a security cost-benefit analysis.
- Using the NSA's INFOSEC Assessment Methodology, conduct an INFOSEC assessment./li>