{"id":50,"date":"2019-03-28T11:22:29","date_gmt":"2019-03-28T15:22:29","guid":{"rendered":"https:\/\/sites.bu.edu\/braude\/?page_id=50"},"modified":"2019-03-28T11:40:41","modified_gmt":"2019-03-28T15:40:41","slug":"met-cs-684-security-policies-and-procedures","status":"publish","type":"page","link":"https:\/\/sites.bu.edu\/braude\/courses\/met-cs-684-security-policies-and-procedures\/","title":{"rendered":"MET CS 684 Security Policies and Procedures"},"content":{"rendered":"<p><em>PLEASE NOTE: THIS IS THE SYLLABUS TO A PREVIOUS FACE-TO-FACE OFFERING OF THIS COURSE<\/em><\/p>\n<p><em>IT IS NOT UP-TO-DATE<\/em><\/p>\n<p><em>IN PARTICULAR, THE TEXTBOOKS ARE NOT NECESSARILY THE ONES CURRENTLY IN USE <\/em><\/p>\n<p><em>THIS OLD SYLLABUS IS LEFT ONLINE TO PROVIDE A SENSE OF HOW THE COURSE WAS DESIGNED IN THE PAST<\/em><\/p>\n<p><em>SOME ASPECTS REMAIN INTACT<\/em><\/p>\n<p><em>FOR INFORMATION, CALL THE DEPARTMENT FOR INFORMATION<\/em><\/p>\n<p><em>(617)353-2566<\/em><\/p>\n<table border=\"1\" cellspacing=\"0\" cellpadding=\"0\">\n<tbody>\n<tr>\n<td width=\"310\" valign=\"top\"><strong>Background of the   Instructor <\/strong>changed if this is red<\/td>\n<td width=\"281\" valign=\"top\"><strong>Learning Objectives <\/strong>changed if this is red<\/td>\n<\/tr>\n<tr>\n<td width=\"310\" valign=\"top\"><strong>Contacting   Eric Braude <\/strong>changed if this is red<\/td>\n<td width=\"281\" valign=\"top\"><strong>Plagiarism   Warning <\/strong>changed if this is red<\/td>\n<\/tr>\n<tr>\n<td width=\"310\" valign=\"top\"><strong>Evaluation of Students <\/strong>changed   if this is red<\/td>\n<td width=\"281\" valign=\"top\"><strong>Policies &#8211; Miscellaneous<\/strong> changed   if this is red<\/td>\n<\/tr>\n<tr>\n<td width=\"310\" valign=\"top\"><strong>Forums: Past and Present <\/strong>changed if this is red<\/td>\n<td width=\"281\" valign=\"top\"><strong>Textbooks and Materials <\/strong>changed if this is red<\/td>\n<\/tr>\n<tr>\n<td width=\"310\" valign=\"top\"><strong>Home Page   of Eric Braude <\/strong>changed if this is red<\/td>\n<td width=\"281\" valign=\"top\"><strong>Topics, Class Dates &amp;   Readings <\/strong>changed if this is red<\/td>\n<\/tr>\n<tr>\n<td width=\"310\" valign=\"top\"><strong>Homework   and Due Dates <\/strong>changed if this is red<\/td>\n<td width=\"281\" valign=\"top\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<hr size=\"2\" \/>\n<h2>Description:<\/h2>\n<p>This course enables IT professional leaders to identify emerging security risks and implement security policies to support organizational goals. Discussion of methodologies for identifying, quantifying, mitigating and controlling risks. Students implement IT risk management plans that identify alternate sites for processing mission-critical applications, and techniques to recover infrastructure, systems, networks, data and user access. The course also discusses topics such as disaster recovery, handling information security; protection of property, personnel and facilities; protection of sensitive and classified information, privacy issues, and criminal terrorist and hostile activities.<\/p>\n<hr size=\"2\" \/>Learning Goals<\/p>\n<ul>\n<li>Understand the common Information      Systems Security models<\/li>\n<\/ul>\n<ul>\n<li>Review CIA characteristics \u2013 confidentiality, integrity and availability<\/li>\n<\/ul>\n<ul>\n<li>Understand security measures from      Technology, Policy &amp; Practice and Education\/Training\/Awareness      dimensions.<\/li>\n<li>Understand risk management \u2013      identification, quantification, response and control.<\/li>\n<li>Learn disaster recovery procedures and      countermeasures for the business enterprise.<\/li>\n<\/ul>\n<hr size=\"2\" \/>\n<h2>Textbook and Materials<\/h2>\n<p>Information Security Policies and Procedures: A Practitioner\u2019s Reference by Thomas R. Peltier, Second edition, Auerbach, ISBN 0-8493-1958-7<\/p>\n<p><em>Guide to Disaster Recovery<\/em> Erbschloe, M. (2003) Thomson Course Technology ISBN 9 780619 131227<\/p>\n<p><em>Security Policies and Procedures: Principles and Practices <\/em>Sari Greene (2005) Prentice Hall ISBN 0-13-186691-5<\/p>\n<hr size=\"2\" \/>\n<h2>Evaluation of Students<\/h2>\n<p>Absorbing and creating security system policies will be expected of all students.\u00a0 To attain excellence, students will be expected to create original analyses and comparisons.\u00a0 The course grade will be computed from the following<\/p>\n<p>Weekly assignments: 35%<\/p>\n<p>Weekly quizzes: 15%<\/p>\n<p>Class participation: 20%<\/p>\n<p>Final: 30%<\/p>\n<p><span style=\"text-decoration: underline;\">Class Participation<\/span><\/p>\n<p>Students are required to participate in class or online discussions because this is an effective and, for many, an enjoyable way to learn.\u00a0 Participation is evaluated as follows.<\/p>\n<p>Make a note of the substantive comments that you make in class or sent to the class via the class site.\u00a0 I often ask question of the class to encourage participation.\u00a0 You are encouraged to participate in class at all times in any case.\u00a0 At any time prior to one week before the final, submit these.\u00a0 Each should consist of the date, the context of the discussion at the time, and a short paragraph of what you said, a half page at the most.\u00a0 Here are some <em>context<\/em> examples.<\/p>\n<ul>\n<li><em>We were discussing how to obtain buy-in from developers for security policies:<\/em><\/li>\n<li>Responding to a comment raised by another student concerning the use of UML inheritance:<\/li>\n<li>Responding to a question put to the class by the professor:<\/li>\n<li>Responding to a question by a student:<\/li>\n<\/ul>\n<p>You are reminded that plagiarism is taken very seriously by the Boston University community; so don\u2019t create imaginary comments, including material from the Internet.\u00a0 The <span style=\"text-decoration: underline;\">criteria<\/span> for participation are as follows:<\/p>\n<p><em>a<\/em><em>. Proportion of substantive contributions. <\/em>This is the <em>percentage<\/em> of documented contributions that have significant content.\u00a0 75% would be a good fraction.\u00a0 95% is definitely excellent<\/p>\n<p><em> <\/em><\/p>\n<p><em>b<\/em><em>. Number of substantive contributions. <\/em>This counts the <em>number<\/em> of substantive contributions.\u00a0 In a class of 15, two per class would be good.\u00a0 Larger classes result necessarily in proportionately lower contribution per person.<\/p>\n<p>g. <em>Evenness of contributions<\/em>.\u00a0 This measures the uniformity of your contributions throughout the semester.\u00a0 A contribution every week would be good in this respect.<\/p>\n<p><span style=\"text-decoration: underline;\">Late homework<\/span> will not be accepted unless there is a reason why it was <em>impossible<\/em> to perform the work in time given work and emergency conditions.\u00a0 In that case, e-mail the written reason should be attached to the homework, which will be graded on a pass\/fail basis if the reason is accepted by me.<\/p>\n<hr size=\"2\" \/>\n<h2>Warning concerning plagiarism<\/h2>\n<p>Please cite all references and uses of the work of other.\u00a0 All instances of plagiarism must be reported to the College for action.\u00a0 e-mail, see or call me if you have any doubts about the proper use of others\u2019 material. In any case, clearly acknowledge all sources in the context they are used, including code, of course.<\/p>\n<hr size=\"2\" \/>\n<h2>Syllabus<\/h2>\n<p>1.\u00a0 <span style=\"text-decoration: underline;\">Introduction and Threats to Enterprise Security<\/span><\/p>\n<p>1A: Introduction and Threats<\/p>\n<ul>\n<li>Vulnerabilities<\/li>\n<li>The U.S.      National Level<\/li>\n<li>Introduction to Risk Thinking<\/li>\n<\/ul>\n<p>1B: An Overview of Security Responses<\/p>\n<p>Readings: Peltier 287-306; 259-263<\/p>\n<p>Greene Most Helpful: 65 \u2013 72; Additional: 72 \u2013 81<\/p>\n<p>2.\u00a0 <span style=\"text-decoration: underline;\">I.T. Enterprise Security Issues<\/span><\/p>\n<p>2A: Common Enterprise Security Issues<\/p>\n<ul>\n<li>Ethical Issues<\/li>\n<li>Legal and Regulatory Issues (Sarbanes-Oxley, HIPAA, FDA, etc.)<\/li>\n<li>Asset Security<\/li>\n<li>Security Risk<\/li>\n<\/ul>\n<p>2B: Specialized Security Issues<\/p>\n<ul>\n<li>Security in a connected world\u00a0 (India,      Ireland,      \u2026.)<\/li>\n<li>Runtime security<\/li>\n<li>Other security issues<\/li>\n<\/ul>\n<p>Readings:\u00a0 Peltier 367-370<\/p>\n<p>Greene Most Helpful: 387 \u2013 396, 425 \u2013 443<\/p>\n<p>Additional: 397-423 page through: 117-137; 425-455; 463-481<br \/>\nSee references to risks via index as needed<\/p>\n<p>3.\u00a0 <span style=\"text-decoration: underline;\">Security Policies, Standards and Procedures<\/span><\/p>\n<p>3A: Security Policies<\/p>\n<ul>\n<li>Rationale for Policies, Standards and Procedures<\/li>\n<li>Preparing and Gathering Information<\/li>\n<li>Policy Parameters<\/li>\n<li>Policy Tiers<\/li>\n<li>Enterprise-Tier Policies<\/li>\n<li>Topic-Tier Policies<\/li>\n<li>Application-Tier Policies<\/li>\n<li>Asset Classification<\/li>\n<\/ul>\n<p>3B: Security Standards and Procedures<\/p>\n<p>Readings: Peltier 47-80, 113-162 and 199-241<\/p>\n<p>Greene Most Helpful: 1-25, 35 \u2013 51, 91-106, 185 &#8211; 203<\/p>\n<p>4.\u00a0 <span style=\"text-decoration: underline;\">I.T. Operational Security Management<\/span><\/p>\n<p>4A: Common Operational Security Management<\/p>\n<ul>\n<li>Quality Assurance in Software Development<\/li>\n<li>Security in system development<\/li>\n<\/ul>\n<p>4B: Specialized Issues in Operational Security Management<\/p>\n<ul>\n<li>The Need to Communicate Security Policies<\/li>\n<li>Program Planning Principles<\/li>\n<li>Scope and Approvals<\/li>\n<li>Assessment of Security       State and Needs<\/li>\n<li>Program Aspects<\/li>\n<li>Implementation<\/li>\n<li>Maintenance<\/li>\n<\/ul>\n<p>Readings: Peltier 325-358<\/p>\n<p>Greene Most Helpful: 311 \u2013 325; Additional: 325-337<\/p>\n<p>5.\u00a0 <span style=\"text-decoration: underline;\">I.<\/span><span style=\"text-decoration: underline;\"> T. <\/span><span style=\"text-decoration: underline;\">B<\/span><span style=\"text-decoration: underline;\">usiness Continuity: Preparation<\/span><\/p>\n<p>5A: An introduction to business continuity and disaster recovery<\/p>\n<ul>\n<li>Reviewing business continuity concepts<\/li>\n<li>Establishing principles of disaster recovery planning<\/li>\n<li>Reviewing steps for disaster recovery planning<\/li>\n<li>Preparing to develop a disaster recovery plan<\/li>\n<\/ul>\n<p>5B: Preparing for I.T. continuity<\/p>\n<ul>\n<li>Assessing risks<\/li>\n<li>Prioritizing assets for recovery<\/li>\n<li>Developing plans and procedures<\/li>\n<li>Learning organizational relationships<\/li>\n<\/ul>\n<p>Readings: Erbschloe Chapters 1-6<\/p>\n<p>Greene Most Helpful: 351 &#8211; 365<\/p>\n<p>6.\u00a0 <span style=\"text-decoration: underline;\">Implementation of Disaster Recovery and Continuing Operations<\/span><\/p>\n<p>6A: Recovering from disasters<\/p>\n<ul>\n<li>Responding to attacks<\/li>\n<li>Implementing recovery plans<\/li>\n<\/ul>\n<p>Reading: Erbschole Chapter 12 (page 317-343)<\/p>\n<p>6B: Ongoing Quality<\/p>\n<ul>\n<li>Learning from disasters<\/li>\n<li>Measuring quality<\/li>\n<li>Managing ongoing quality processes<\/li>\n<\/ul>\n<p>Review for Final<\/p>\n<p>Readings: Erbschloe Chapter 12 (317-343);\u00a0 Chapter 3 is background reading for the first part of\u00a0 lecture 6B<\/p>\n<p>Greene Most Helpful: 365 &#8211; 375<\/p>\n","protected":false},"excerpt":{"rendered":"<p>PLEASE NOTE: THIS IS THE SYLLABUS TO A PREVIOUS FACE-TO-FACE OFFERING OF THIS COURSE IT IS NOT UP-TO-DATE IN PARTICULAR, THE TEXTBOOKS ARE NOT NECESSARILY THE ONES CURRENTLY IN USE THIS OLD SYLLABUS IS LEFT ONLINE TO PROVIDE A SENSE OF HOW THE COURSE WAS DESIGNED IN THE PAST SOME ASPECTS REMAIN INTACT FOR INFORMATION, [&hellip;]<\/p>\n","protected":false},"author":2828,"featured_media":0,"parent":22,"menu_order":5,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/50"}],"collection":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/users\/2828"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/comments?post=50"}],"version-history":[{"count":1,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/50\/revisions"}],"predecessor-version":[{"id":51,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/50\/revisions\/51"}],"up":[{"embeddable":true,"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/pages\/22"}],"wp:attachment":[{"href":"https:\/\/sites.bu.edu\/braude\/wp-json\/wp\/v2\/media?parent=50"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}