Secure your place for the October 2026 intake.



MC03 - Information Security Management

Managing cyber risk, governance, and resilience in modern organisations.

Credits

7.5 ECTS

Semester

2 Semester

Delivery

Online

Duration

13 weeks

Language

English

About This Course

This is a second-semester course in the MBA in Advanced Cybersecurity Technologies &
Governance
Information Security Management equips students to manage cyber risk and protect organisational assets. Using recognised ISO and NIST frameworks, students learn to assess threats and vulnerabilities, prioritise risks, select security controls, develop policies and strengthen cybersecurity culture. The course also covers contingency planning, data protection and professional development.

What You Will Learn


Cybersecurity Governance & Frameworks

  • Explain the importance of cybersecurity governance and information security management.
  • Understand core concepts including assets, threats, threat actors, vulnerabilities, controls and risk.
  • Examine recognised frameworks and standards including ISO/IEC 27001, ISO/IEC 27005 and the NIST Cybersecurity Framework.


Risk Identification, Assessment & Treatment

  • Apply structured risk-assessment approaches based on NIST SP 800-30 and ISO/IEC 27005.
  • Use threat-modelling and vulnerability-assessment techniques to identify potential cyber threats and weaknesses.
  • Compare risk-treatment strategies and justify the selection of appropriate security controls.


Security Culture, Policy & Resilience

  • Create security policies tailored to organisational threats and vulnerabilities.
  • Design awareness and training activities that strengthen cybersecurity culture.
  • Support incident response, business continuity, disaster recovery and GDPR-aligned data protection.

Your 13-Week Journey

Here’s how your learning unfolds

Week 1 – Introduction to Information Security Management

Explore core security principles, governance, data breaches and the CIA triad.

Week 2 – Information Security Management Frameworks

Examine ISO/IEC 27001, the NIST Cybersecurity Framework and the PDCA cycle.

Week 3 – Risk Assessment Based on NIST SP 800-30

Identify threats, vulnerabilities, likelihood, impact and overall risk.

Week 4 – Building a Cybersecurity Culture

Design awareness initiatives that strengthen organisational cybersecurity culture.

Week 5 – Risk Assessment Based on ISO/IEC 27005

Assess organisational assets, threats, vulnerabilities and risk levels.

Week 6 – Risk Identification: Threat Modelling

Apply techniques such as STRIDE, attack trees and MITRE ATT&CK.

Week 7 – Risk Identification: Vulnerability Assessment

Identify and prioritise vulnerabilities using CVE, CWE, CVSS and OWASP.

Week 8 – Risk Analysis and Evaluation

Analyse and prioritise risks using qualitative and quantitative methods.

Week 9 – Risk Treatment

Compare treatment options and select appropriate security controls.

Week 10 – Professional Development

Plan your cybersecurity career development using the ENISA ECSF.

Week 11 – Security Policies

Develop effective organisational security policies, standards and procedures.

Week 12 – Contingency Planning

Support incident response, business continuity and disaster recovery planning.

Week 13 – Data Protection

Apply GDPR principles and conduct data protection impact assessments.


Empty space, drag to resize

Skills You Will Gain

Cyber Risk Strategy & Assessment

  • Develop an organisation’s cybersecurity risk-management strategy.
  • Apply risk-assessment methodologies to identify assets, threats and vulnerabilities.
  • Analyse and evaluate risk to support informed treatment decisions.

Threat Analysis, Controls & Resilience

  • Apply threat-modelling and vulnerability-assessment techniques.
  • Select and justify security controls aligned with recognised standards and best practices.
  • Contribute to incident-response, business-continuity and disaster-recovery planning.

Security Policy, Culture & Professional Leadership

  • Create security policies aligned with organisational threats and vulnerabilities.
  • Design awareness-raising activities and promote a strong cybersecurity culture.
  • Use the ENISA ECSF and other professional frameworks to plan continued professional development.