Logo

Information Systems Security Management

Code: 102161
Credits: 6
2026/2027
Degree programme Type Course
Business and Information Technology OP 4
Aeronautical Management OP 4

Contact lecturer

Name :
Miguel Angel Cara Ruiz
Email :
miguelangel.decara@uab.cat

Teaching staff

Miguel Angel Cara Ruiz

Group languages

You can consult this information at the end of the document.

Prerequisites

It would be advisable to follow also the course on networks offered in the degree (102169-Xarxes)

Objectives

Course Objectives:

The course aims to provide students with a global, applied and progressive understanding of information security in organisations, combining technical foundations, security governance, risk management and practical application through a continuous case study.

  • Understand the fundamentals of cybersecurity and information security in an organisational context.
  • Analyse the state of information security in an organisation from a global perspective, taking into account assets, processes, risks, controls and business needs.
  • Provide students with the technical and management skills required to understand the technological environment of information security.
  • Understand the information security needs of organisations and communicate them to Management.
  • Become familiar with the legal frameworks, international standards, regulations and best practices that affect information security.
  • Identify and assess information security risks, proposing appropriate and prioritised mitigation measures.
  • Understand the main technical areas of security: identity management, passwords and cryptography, networks, data protection, cloud, IoT, application security and incident response.
  • Assess the impact of information security on business continuity, data protection, regulatory compliance and Management decision-making.
  • Apply the knowledge acquired in a practical case study through progressive deliverables: inventory of assets and processes, initial assessment, risk analysis, project plan, security architecture and improvement proposals.


Detailed competences

  • Demonstrate a global understanding of information security in organisations.
  • Understand the alignment between organisational objectives and information security objectives.
  • Identify the state of security from both an organisational management perspective and a technical perspective.
  • Identify gaps in corporate security governance and propose lines of action for improvement.
  • Identify information security risks and propose appropriate treatment measures.
  • Understand the main technical areas of information security, including identity, cryptography, networks, data protection, cloud, IoT, applications and incident response.
  • Demonstrate the ability to communicate technical security concepts to audiences without specialised knowledge, both orally and in writing.
  • Apply the knowledge acquired in continuous assessment exercises, presentations and deliverables linked to the course case study.


Detailed learning Outcomes

  • Assess the state of information security in an organisation, in line with its sector of activity, legal context, exposure and level of risk acceptable to Management.
  • Define the initial strategy for implementing or improving an information security management system.
  • Apply a basic risk analysis methodology to identify threats, vulnerabilities, impacts and mitigation measures.
  • Define a prioritised security project plan, justifying the proposed actions according to criteria of risk, impact and alignment with the business.
  • Explain the role of reference frameworks, standards and best practices in the organisation, management and continuous improvement of information security.
  • Assess the importance of data protection, identity management, cryptography and application security within a corporate security strategy.
  • Understand the risks and security criteria associated with the use of cloud solutions, IoT environments and emerging technologies, including security in artificial intelligence.
  • Analyse incident response situations from an organisational and technical perspective, identifying detection, containment, communication and subsequent improvement needs.

Learning outcomes

Business and Information Technology
  • CM26 (Comply with ethical, legal and intellectual property principles in relation to the processing of private information in the business field.) Comply with ethical, legal and intellectual property principles in relation to the processing of private information in the business field.
  • KM22 (Identify data management and communication systems based on the needs of an organisation, as well as their governance.) Identify data management and communication systems based on the needs of an organisation, as well as their governance.
  • SM16 (Distinguish security management activities and their implication in the design and implementation of information systems.) Distinguish security management activities and their implication in the design and implementation of information systems.

Contents

Information Security and Cybersecurity

  • Understand what is meant by information security and cybersecurity in the context of organisations.
  • Identify the importance of information security in corporate environments, considering its impact on the business, operational continuity, data protection and decision-making.
  • Analyse the main concepts of confidentiality, integrity, availability, authentication, traceability and accountability.
  • Understand the evolution of cybersecurity threats and risks in current organisations.

Governance, Reference Frameworks and Security Management

  • Know the main reference frameworks, standards and best practices applicable to information security.
  • Understand the role of reference frameworks in the organisation, management and continuous improvement of security.
  • Identify how information security objectives are aligned with the strategic and operational objectives of the organisation.
  • Analyse the security gaps of an organisation and propose lines of action for improvement.

Risk Analysis and Management

  • Understand the importance of risk analysis in information security management.
  • Identify assets, processes, threats, vulnerabilities, impacts and controls within a corporate environment.
  • Apply a basic risk analysis methodology to assess the security posture of an organisation.
  • Define mitigation measures and prioritised action plans according to risk, impact and feasibility criteria.

Identity Management, Passwords and Cryptography

  • Understand the importance of identity and access management in corporate security.
  • Analyse the risks associated with the use of passwords, weak authentication and poor privilege management.
  • Know the basic principles of cryptography and its application in the protection of information.
  • Differentiate between symmetric encryption, asymmetric encryption, hash functions, digital certificates and digital signatures.

Network Security and Technological Environments

  • Understand the fundamentals of security in communication networks.
  • Identify common risks in corporate network architectures and possible protection measures.
  • Analyse the role of security controls in networks, segmentation, monitoring and perimeter protection.
  • Relate network security to the other areas of corporate security.

Data Protection and Regulatory Compliance

  • Understand the importance of data protection within an information security strategy.
  • Identify the main legal, normative and regulatory requirements that affect the security and protection of information.
  • Analyse the impact of regulatory compliance on corporate security management.
  • Understand the relationship between data protection, security governance, risks and technical controls.

Cloud Security, IoT and Emerging Technologies

  • Understand the main risks associated with the use of cloud solutions in corporate environments.
  • Identify security criteria applicable to cloud services, shared responsibility models and protection of information in the cloud.
  • Analyse the specific risks of IoT environments and connected devices.
  • Understand the emerging risks linked to new technologies, including security in artificial intelligence.

Application Security

  • Understand the fundamentals of application security and its importance in the technology lifecycle.
  • Identify common risks in corporate applications and exposed services.
  • Relate application security to data protection, identity, network security and vulnerability management.

Incident Response

  • Understand the security incident management and response cycle.
  • Identify the main phases of detection, analysis, containment, eradication, recovery and subsequent improvement.
  • Analyse security incidents from a technical and organisational perspective.
  • Understand the importance of communication, documentation and decision-making during an incident.

Applied Case Study

  • Apply the knowledge acquired in a continuous practical case study on information security.
  • Prepare an inventory of assets, processes and an initial assessment of the case.
  • Carry out a risk assessment and define a security project plan.
  • Propose a security architecture consistent with the needs of the case.
  • Identify additional improvements and justify their priority according to risk, impact and alignment with the business.
  • Present and defend the conclusions of the case study in a clear, structured way, aimed at both technical and non-technical audiences.

Learning activities and methodology

Title Hours ECTS Learning outcomes
Teamwork 20 0.8
Individual work 50 2
Problem and exercise solving 15 0.6
Theoretical Classes and Case Studies 30 1.2
Report writing and Case Study preparation 32 1.28

General Aspects

1. Faculty-student relationship

The general and relevant information about the course will be published on the Virtual Campus, or on the equivalent space provided by the university. This space will include the contents of the teaching guide, the dates for continuous assessment, the deadlines and conditions for submitting assignments, support materials and any other information required to follow the course.

The course planning may be subject to adjustments due to organisational or academic reasons, or due to unforeseen circumstances. If any changes to the schedule occur, they will be communicated through the Virtual Campus, which will be considered the usual communication channel between faculty and students.

2. Languages

Classes will mainly be conducted in Catalan or Spanish, although the use of technical terms in English will be common. Written or support material for the course, such as notes, bibliography, references, practical assignment statements, exercises or case studies, may be provided in Catalan, Spanish or English. In this regard, the use of English may be common, especially in technical materials or specialised references.

The final exam and the reassessment exam will be written in Catalan or Spanish. Answers to exams, exercises, practical assignments and presentations may be submitted in Catalan, Spanish or English.


Activities during the course


Lectures, case studies and exercise-solving sessions

During the theoretical sessions, the fundamental contents of the course will be presented, which are necessary to understand the main areas of information security in organisations.

These sessions will address, among other aspects, the fundamentals of cybersecurity, reference frameworks, risk analysis, identity management, cryptography, network security, data protection, cloud and IoT security, application security, incident response and emerging technologies, including security in artificial intelligence.

Classes may combine theoretical explanation, analysis of examples, exercise solving, case discussion and continuous assessment activities. Likewise, the necessary ways to expand or deepen the contents covered in class will be indicated.


Problem-based learning, cooperative learning, workshops and practical exercises

Part of the course will use active learning methodologies and applied exercises, in which students will have to face situations close to the professional practice of information security in corporate environments.

During the course, individual and group activities may be carried out, supervised by the course teaching team. These activities will be aimed at the practical application of the contents covered in class, especially through the development of the course case study.

Teamwork and the collaborative exchange of information and tools for problem solving will be encouraged. However, the final learning process must be individual, supported by each student’s autonomous work, which must complement and enrich the work initiated in the guided sessions of the course.

Supervised activity, through scheduled tutorials and consultations carried out during the course, will also be an important tool for acquiring the knowledge and competencies provided by the course.


Annotation: within the schedule set by the centre or degree programme, 15 minutes of one class will be reserved for students to evaluate their lecturers and their courses or modules through questionnaires.

Assessment

Continuous assessment activities

Title Weight Hours ECTS Learning outcomes
Classwork, teamwork and participation 60% 0 0 CM26, KM22, SM16
Exams 40% 3 0.12 CM26, KM22, SM16

This subject/module does not offer the option for comprehensive evaluation.

The evaluation consists of two complementary parts:

(1) Practices, Exercises and Participation (6 points):

  • Exercise (s) of problem-based learning, teamwork or individual work, class presentation of results and other tests to be determined. If the weight of the activity is 1 or more points, a notice will be published on the virtual campus at least one week in advance.
  • These activities, because they are continuously evaluated, can not be recovered. They will be delivered within the established deadlines and conditions that will be made public in the Virtual Campus of the subject.

(2) Exams/Theory (4 points):

  • Final written test on concepts and aspects dealt with during the course.
  • Mid-term exam.

General conditions to pass:


To pass the subject it is necessary to obtain 5 points having reached the following minimums:

  • Practices Exercises and Participation: minimum 2.5 points out of 6
  • Theory: minimum 1.5 points out of 4

Calculation of the final grade:

  • If the above mentioned minimums are reached, the final grade will consist of at least the sum of the marks obtained in the two parts. The professor may, however, increase it according to objective and equitable criteria. A student obtaining at least a grade of 5 will pass, whereas he/she will fail if the grade is less than 3.5; otherwise the student is allowed to go through the retake process described below.
  • If the minimum of the Practices, Exercises and Participation mark is not reached, the final grade of the subject will be that of this part and thus the student fails.
  • If the minimum of the Theory part is not reached, and the sum of the marks obtained in both parts is less than 3.5 points, the final grade will be this sum and therefore the student fails.
  • If the minimum of the Theorypart is not reached, and the sum of the marks obtained in both parts is greater than or equal to 3.5 points, the student is allowed to go through the retake process described below.

Any student who has made at least two deliveries in the continuous evaluation can not be considered as \"non evaluable\"..


Calendar of evaluation activities

The dates of the evaluation activities (exercises, assignments ...) will be announced well in advance during the semester.

The dates of the midterm and final exams are scheduled in the assessment calendar of the Faculty.

\"The dates of evaluation activities cannot be modified, unless there is an exceptional and duly justified reason why an evaluation activity cannot be carried out. In this case, the degree coordinator will contact both the teaching staff and the affected student,and a new date will be scheduled within the same academic period to make up for the missed evaluation activity.\" Section 1 of Article 115. Calendar of evaluation activities (Academic Regulations UAB). Students of the Faculty of Economics and Business, who in accordance with the previous paragraph need to change an evaluation activity date must process the request by filling out an Application for exams' reschedulehttps://eformularis.uab.cat/group/deganat_feie/application-for-exams-reschedule

Grade revision process

After all grading activities have ended, students will be informed of the date and way in which the course grades will be published. Students will be also be informed of the procedure, place, date and time of grade revision following University regulations.

Retake Process

\"To be eligible to participate in the retake process, it is required for students to have been previously been evaluated for at least two thirds of the total evaluation activities of the subject.\" Section 3 of Article 112 ter. The recovery (UAB Academic Regulations). Additionally, it is required that the student to have achieved an average grade of the subject between 3.5 and 4.9.

The date of the retake exam will be posted in the calendar of evaluation activities of the Faculty. Students who take this exam and pass, will get a grade of 5 for the subject. If the student does not pass the retake, the grade will remain unchanged, and hence, student will fail the course.

Irregularities in evaluation activities

In spite of other disciplinary measures deemed appropriate, and in accordance with current academic regulations, \"in the case thatthe student makes any irregularity that could lead to a significant variation in the grade of an evaluation activity, it will be graded with a 0, regardless of the disciplinary process that can be instructed. In case of various irregularities occurin the evaluation of the same subject, the final grade of this subject will be 0\". Section 10 of Article 116. Results of the evaluation. (UAB Academic Regulations).


The completion of assessment activities is subject to the provisions set out in this course guide and in the "Policy of the School of Economics and Business on the Detection of Irregularities during Assessment Activities", which regulates the conditions under which assessment tasks are conducted and the procedures applicable in cases where indications of irregularities are detected. Students are encouraged to consult the policy.

Bibliography

You'll find it in the Virtual Classroom

Software

Only software within the conventional office automation group is used in the course.

Course groups and languages

The information provided is provisional until November 30. After this date, you will be able to consult the language of each group through this link. To access the information, you will need to enter the course CODE

Type of teaching Group Language Semester Shift
(TE) Theory 20 Catalan first semester afternoon
(PAUL) Classroom practices 201 Catalan first semester afternoon