ISM 603 Master Syllabus

To print: Right-click and choose “Print,” then follow your browser’s print settings.
To download: Right-click and choose “Print,” then select “Save as PDF.”

Costello College of Business Logo

 

Enterprise Hall 4400 University Drive, MS 1B1 
Fairfax, Virginia 22030 
Phone: (703) 993-1880 
Fax: (703) 993-1867

Fundamentals of Information Security – ISM 603
(Instructor Reserves the Right to Change the Syllabus without Notice. Updated 2/28/25.)

 

ISOM 603 Course Information Instructor
Date/Time: ONLINE Name:  
Location: ONLINE Email:  

 

Course Description and Objectives

This course will cover foundational technical concepts as well as managerial and policy topics on a variety of information and cyber security topics. The purpose of the course lectures, assignment activities, and examinations are to ensure that students have sufficient technical awareness and managerial competence related to information security and assurance. Students will examine the nature of threats and vulnerabilities, cryptography, software vulnerabilities, managing risk, and security controls. The course focuses on the threats and vulnerabilities that lead to data breach and compromise; how organizations can set up protection measure to mitigate the risk of compromise; how organizations can establish cyber trust when using third party tools and services, as well as utilizing the cloud; and the topic of Business Continuity and Disaster Recovery from a cyber management perspective. Learning Objectives include:

  • Understand the fundamentals of Information Security

  • Understand the fundamental technologies and techniques of information security

  • Understand the best practices of information security management both internally and externally to the organization

  • Understand how to plan for and respond to business continuity issues involving technology and information security

 

Course Prerequisites/Co-requisites

Students accepted into the Information Security Management (ISM) Program, or undergraduate students approved to take ISM courses.

 

Required Materials/Textbooks/Software/Hardware

Blackboard Access

 

Instructor Policies

  • Communications with the Instructor: I prefer email to XXX, and will respond within 2 business days. If you do not hear a response from me within that timeframe, please resend your email. All emails should have in the subject line: Course Number, Section, and title of the question. Please use your GMU email to communicate with me.

  • Office Hours: By appointment, so please send me an email with a suggested time and I’ll confirm if I’m free.

  • Attendance: This is your responsibility. If you miss lectures, then you will miss valuable content. If you miss a quiz or exam, you cannot make it up, and will take a zero for the task.

  • Late Assignments: Not accepted because all assignments are turned in electronically and their due dates are listed here in the syllabus. Excused late assignments require proof and notification ahead of time.

  • Corrupt/Wrong Assignment Submissions: It is your job as the student to ensure that you submit the correct assignment / readable assignment for me to grade. If I cannot read the assignment for any reason or you submit the wrong assignment, you will get an automatic zero.

  • Cheating & Plagiarism: This will not be tolerated and will result in you receiving a zero for the assignment / exam. Furthermore, the administration may be involved when cheating & plagiarism is suspected or caught.

 

Course Grading, Examinations, & Grades Composition

Grading for the course will be based on total points earned by the end of the course. Final course letter grade assignments will be as follows:

Grading Scale
A+ >=97 A 92-96 B 80-91 C 70-79 F <70
Grade Breakdown Percent
Information Security Knowledge Quizzes (6) 30%
Security Incident Activities (5) 15%
Analyzing an Organization's Security Activities (5) 20%
Guest Lecture Quizzes (3) 15%
Cyber Hygiene Self-Assessment 20%
Total 100%

Information Security Knowledge Quizzes (6 @ 5% Each, 30% Total)
These quizzes are open book and focuses on the materials delivered in the lecture videos and readings. While the quizzes are open book, students need to know the material well prior to taking the quizzes because it will have a 30min timer once they are started. Students are able to take the quizzes as many times as they want until the due date, but only the student’s last quiz attempt will be graded.

Security Incident Activities (5 @ 3% Each, 15% Total)
Students are given an article to read and analyze. Students will then respond to (in a discussion post) the activity’s prompt. Students can optionally respond to (comment / reply) to their peers’ posts.

Analyzing an Organization’s Security Activities (5 @ 4% Each, 20% Total)
Each student is randomly assigned on organization to perform security assessments on for the semester. For each activity, the student will need to respond to the questions provided in a discussion post within 4 days of the activity’s start date. Then they will need to respond (comment / reply) to a minimum of two other posts by their peers as instructed in the assignment before the activity’s due date.

Guest Lecture Quizzes (3 @ 5% Each, 15% Total)
There are three guest lectures throughout the semester. After listening to each guest lecture, students are required to take the corresponding quiz. Each quiz is open book and focuses on the content delivered by the particular guest lecturer. While the exam is open book, students need to know the material well prior to taking the quiz because it will have a 30min timer once the quiz is started. Students are able to take the quizzes as many times as they want until the due date, but only the student’s last quiz attempt will be graded.

Cyber Hygiene Self-Assessment Assignment (20%)
After completion of the course’s lecture, students will need to apply the content they have learned to their everyday work and personal life through this self-assessment exercise. More information on this assignment (and template) will be released on blackboard when the time comes.

 

Schedule - NOTE: The instructor reserves the right to adjust the schedule.

Week/Date Course Content Assignment Due
Week 1
8/27

Introduction to Information Security

  • The Cyber Environment & Current/Emerging Threats

  • Information Security Fundamentals & Principles

  • Analyzing an Organization’s Security Activity 1

  • Quiz 1 due 9/2

  • Analyzing Organization Security Activity 1 due 9/2

Week 2
9/3

Technical Information Security (Part 1 of 2)

  • Cryptography Basics

  • Identity & Access Management

  • Security Incident Activity: Colonial Pipeline

  • Quiz 2 due 9/9

  • Colonial Pipeline Security Incident Activity due 9/9

Week 3
9/10

Technical Information Security (Part 2 of 2)

  • Data & Application Security

  • Security Incident Activity: Target

  • Analyzing an Organization’s Security Activity 2

  • Quiz 3 due 9/16

  • Target Security Incident Activity due 9/16

  • Analyzing Organization Security Activity 2 due 9/16

Week 4
9/17

Information Security Beyond the Perimeter (Part 1 of 2)

  • Supply Chain Cyber Security Overview

  • Security Incident Activity: SolarWinds

  • Analyzing an Organization’s Security Activity 3

  • Quiz 4 due 9/23

  • SolarWinds Security Incident Activity due 9/23

  • Analyzing Organization Security Activity 3 due 9/23

Week 5
9/24

Information Security Beyond the Perimeter (Part 2 of 2)

  • Cloud Security & Managed Security Service Providers

  • Security Incident Activity: CapitalOne

  • Analyzing an Organization’s Security Activity 4

  • Quiz 5 due 9/30

  • CapitalOne Security Incident Activity due 9/30

  • Analyzing Organization Security Activity 4 due 9/30

Week 6
10/1

Preparing for the Security Incident(s)

  • Incident Response & Business Continuity

  • Security Incident Activity: Equifax

  • Analyzing an Organization’s Security Activity 5

  • Quiz 6 due 10/7

  • Equifax Security Incident Activity due 10/7

  • Analyzing Organization Security Activity 5 due 10/7

Week 7
10/8

&

Week 8
10/15

Guest Lectures

  • ICS/SCADA Cyber Security

  • 5G Cyber Security

  • Cyber Operations

Optional LinkedIn Learning Modules

  • Cybersecurity for Executives

  • Building & Managing a Cybersecurity Program

  • Influence Skills for Leaders & Managers

  • Presenting to Senior Executives

  • Quiz 7 due 10/18

  • Quiz 8 due 10/18

  • Quiz 9 due 10/18

  • Cyber Hygiene Self-Assessment due 10/18

 

Academic Integrity and Honor Code

The Honor Code is an integral part of university life. Students are responsible, therefore, for understanding the code’s provisions. In the spirit of the code, a student’s word is a declaration of good faith acceptable as truth in all academic matters. Cheating and attempted cheating, plagiarism, lying, and stealing of academic work and related materials constitute Honor Code violations. To maintain an academic community according to these standards, students and faculty must report all alleged violations to the Honor Committee. Any student who has knowledge of, but does not report, a violation may be accused of lying under the Honor Code. Please refer to http://honorcode.gmu.edu for further details. When in doubt (of any kind), please ask the instructor for guidance and clarification.

Graduate Honor Code Recommendations (2019 – present) 

Costello College of Business Recommendations for Honor Code Violations Graduate Programs
Honor Code Violation Recommended Sanction
For example: Lying, plagiarizing, cheating, orstealing in academic matters An F in the class
If the violation is considered to be egregious An F in the class, and consideration for dismissal from the Costello College of Business

First Offense Impact:

  • At the very least: GPA is impacted, may require taking additional courses to raise GPA to required 3.0 to graduate.

    • Required course: Must re-take course. May not be offered for 6-12 months so delays graduation. o 

    • Elective: Will need to re-take same course or take another elective. Likely to delay graduation.

  • At the worst: If found in violation, and the violation is found to be egregious -- dismissal from the program

Second Offense Impact:

  •  Second Offense Impact:

    • Will automatically trigger academic termination because of two “F” grades

 

Disability Accommodations

If you are a student with a disability and you require academic accommodations, please see me and contact the

Office of Disability Services (ODS) at (703) 993-2474 (http://ods.gmu.edu/), at the beginning of the semester. All

academic accommodations due to disability must be arranged through the ODS and should be made during the

first two weeks of the semester.

 

Campus Notifications

Students are encouraged to subscribe to the Mason Alert system to receive notifications of campus emergencies,

closings, and other situations that could affect class activities. Each classroom has a poster explaining actions to be

taken in different types of crisis. Further information on emergency procedures is available at the Campus

Emergency Response Team Web site. In the event of an emergency, students are encouraged to dial 911.

 

Other Resources

Mason provides many useful resources for students. See http://www.gmu.edu/resources/students/ for a

complete listing of Mason resources for students.

 

Important Dates

Academic Calendar: https://registrar.gmu.edu/calendars/