IS6522 Infrastructure and Security Management for eCommerce

Part I

Course Duration: One Semester(13 weeks)
Credit Units: 3 credits
Level: P6
Medium of Instruction: English
Prerequisites: Nil
Precursors: Nil
Equivalent Courses: IS6523 Information Systems Infrastructure and Security Management
Exclusive Courses: IS6523 Information Systems Infrastructure and Security Management

Part II

Course Aims

The aim of this course is to examine key infrastructural and security issues involved in Electronic Commerce transactions.  A managerial perspective will be adopted throughout.  Both electronic payment infrastructure and transactional security infrastructure will be covered.

Course Intended Learning Outcomes (CILOs)
Upon successful completion of this course, students should be able to:

No.CILOs Weighting
1.

Apply key security technical concepts and tools and the IT risks management to identify and counteract possible threats facing the business organizations.

2
2.

Evaluate different types of audit principles, controls framework, evidence collection and evaluation techniques in the context of Electronic Commerce.

2
3.

Apply good security management principles and key legal issues involved in Electronic Commerce in the design of security policies and operation within organizations.

3
4.

Evaluate security of electronic payment infra-structures for Electronic Commerce.

2
5.

Communicate effectively with the stakeholders to provide appropriate security solutions / consultancy to the business organizations.

1

Teaching and Learning Activities (TLAs)
(Indicative of likely activities and tasks designed to facilitate students’ achievement of the CILOs. Final details will be provided to students in their first week of attendance in this course)

Indicative of likely activities and tasks students will undertake to learn in this course.  Final         details will be provided to students in their first week of attendance in this course.

Seminar:         39 hours

TLA1: Lecture

The following items form the content of the lecture:

  • Threats understanding and security attacking methods
  • Key concepts of IS security principles and tools
  • Information technology risks management
  • IS audit life cycle and IS audit controls framework
  • Electronic payment infrastructure
  • Security management and policy
  • Legal and ethical issues

TLA2: Class Activity

In the seminars, the following activities are used to reinforce the concepts learnt in lectures:

  • Exercises: In form of short questions, cases or article readings of the related subjects for students to have the application of concepts and theories learned in the class to the real world.
  • Group Discussion: group discussions aiming to cultivate critical thinking and application of the concepts to the actual business scenarios.

 

CILO No.TLA1: LectureTLA2: Class ActivityHours/week (if applicable)
CILO 122---
CILO 222---
CILO 322---
CILO 422---
CILO 511---
(1: Minor focus on the ILO; 2: Main focus on the ILO)

Assessment Tasks/Activities
(Indicative of likely activities and tasks designed to assess how well the students achieve the CILOs. Final details will be provided to students in their first week of attendance in this course)

AT1: Class Activity (20%)
It consists of class exercises and discussion.  Each class activity consists of exercises and group discussions to assess students’ understanding of the topics and their abilities to apply their knowledge and skills.
 
AT2: Individual Assignment (40%)
Each student is required on the new developments related to an existing topic to give critical analysis and solution or impact to the business organizations.  A written report will be used to assess student’s competence level in the understanding of new developments based on the foundations of relevant topic.
 
AT3: Project (40%)
Each student will participate in group project (about 4 to 6 students per group) and work on a IS security / audit analysis report. Each group will be required to submit a project paper of detailed findings and recommendations and make a 20-minute presentation.  A well-written report is required to let students demonstrate their ability in applying all the concepts and theories learned in the course to provide a workable solution and consultancy to the business organizations.

ILO No.AT1: Class Activity (20%)AT2: Individual Assignment (40%)AT3: Project (40%)Remarks
CILO 12121: Minor focus on the ILO;
2: Main focus on the ILO
CILO 2212
CILO 3222
CILO 4212
CILO 51 1

Grading of Student Achievement:

Written Examination

ILOExcellentGoodAdequateMarginal
CILO 1

Effectively apply key security technical concepts and tools and the IT risks management to identify and counteract possible threats facing the business organizations.

Accurately apply key security technical concepts and tools and the IT risks management to identify and counteract possible threats facing the business organizations..

Moderately apply key security technical concepts and tools and the IT risks management to identify and counteract possible threats facing the business organizations.

Apply some key security technical concepts and tools and the IT risks management to identify and counteract possible threats facing the business organizations.

CILO 2

Effectively evaluate different types of audit principles, controls framework, evidence collection and evaluation techniques in the context of Electronic Commerce.

Accurately evaluate different types of audit principles, controls framework, evidence collection and evaluation techniques in the context of Electronic Commerce.

Moderately evaluate different types of audit principles, controls framework, evidence collection and evaluation techniques in the context of Electronic Commerce.

Evaluate some different types of audit principles, controls framework, evidence collection and evaluation techniques in the context of Electronic Commerce.

CILO 3

Effectively apply good security management principles and key legal issues involved in Electronic Commerce in the design of security policies and operation within organizations.

Accurately apply good security management principles and key legal issues involved in Electronic Commerce in the design of security policies and operation within organizations.

Moderately apply good security management principles and key legal issues involved in Electronic Commerce in the design of security policies and operation within organizations.

Minimally apply good security management principles and key legal issues involved in Electronic Commerce in the design of security policies and operation within organizations.

CILO 4

Effectively evaluate security of electronic payment infra-structures for Electronic Commerce.

Accurately evaluate security of electronic payment infra-structures for Electronic Commerce.

Moderately evaluate security of electronic payment infra-structures for Electronic Commerce..

Minimally evaluate security of electronic payment infra-structures for Electronic Commerce.

CILO 5

Extensively demonstrate effective communication skills and provide appropriate security solutions / consultancy to the business organizations.

Demonstrate some effective communication skills and provide appropriate security solutions / consultancy to the business organizations.

Demonstrate the basic communication skills and provide appropriate security solutions / consultancy to the business organizations.

Minimally demonstrate some communication skills and provide appropriate security solutions / consultancy to the business organizations.


Part III

Keyword Syllabus

IS Auditing; IS Security Management Practices; Information Technology Risks Management; Controls Framework; Electronic Payment Systems and Infrastructure; Security Policy; Threats; Attacking Methods; Security Principles and Tools; Network Security.

Related Links
Department of Information Systems