BIS 4113 / 6113 BIS Security Management Spring 2015 Class Time: MW 12:30 – 1:45 PM Room: McCool 109 Instructor: Dr. Kent Marett E-Mail: kmarett@cobilan.msstate.edu Class Website: Office: McCool 302H Virtual Office Hours: MW 2:00-3:30 PM (or by appointment) http://misweb.cbi.msstate.edu Go to your instructor’s faculty profile page, then scroll down to the Courses Taught section. Response Time: I will respond to emails within 24 hours. I check my e-mail several times a day. Course Description: (Prerequisite: BIS 3233 or consent of instructor). Three hours lecture. Concepts, skills, tools and techniques involved in management of computer security as it applies to today's business environment. Textbooks (required): CISSP: Certified Information Systems Security Professional Study Guide, 6th Edition by Stewart, Chapple, & Gibson. ISBN-10: 1118314174 | ISBN-13: 978-1118314173 You are strongly encouraged to read the suggested portions of the books before coming to class. See schedule below for details. Software: You must have a primary email account that you check daily. You will also need complete, unfettered access to a personal computer and the Internet. This is necessary for some of the homework assignments and readings that you will be completing. Plus, this class uses the "misweb system" for course management. Your first step in using misweb is to "register" for the system. To do this, go to: http://misweb.cbi.msstate.edu/editor Enter your Banner net id, such as abc123, and your Banner net password. Click on the Log in button. If you have already registered for misweb, you will go straight to your Edit Routine. If you have not previously registered for misweb, you will go to a short form which will allow you to register. Complete and submit the form. Register for misweb immediately! The misweb system gives you a password-protected account that you can use to publish an online student profile page that is accessed through the COBI web site. You need to publish a good page as part of that site, if only to provide your instructor with information about your background. This system is intended to help you provide valuable information to instructors, fellow students, employers, and anyone else who visits COBI’s web site. To go to the misweb system in the future, go to: http://misweb.cbi.msstate.edu Grading: The following table shows the allocation of the weights that will be assigned when calculating your final grade. Exams (3) 20% each Business Security Review 30% total Sub-Components Deliverable 1 10% Deliverable 2 10% Paper / Presentation 80% A 90.0 – 100 B 80.0 – 89.99 C 70.0 – 79.99 D 60.0 – 69.99 F < 59.99 Assignments 10% Grade Appeals: I am willing to review grades. If you wish to appeal a grade, you should submit a written explanation to the instructor summarizing why you believe your grade should be modified. Appeals must be made within one week of the score being made available to you. Exam and Assignment Policy: If, for some reason*, you must miss class, or one of the exams or quizzes, you are obligated to contact me beforehand so we can arrange an alternative. The same goes for dates assignments are due. There will be no makeup exams after the fact, and late assignments will likely not be accepted. * - a university-approved reason, such as severe illness, death, job interview, participating in an athletic event, etc. See student handbook. Assignments: There will be a few homework exercises assigned to you throughout the semester. These assignments will typically be hands-on exercises that reinforce classroom material, and depending on the assignment and should be completed individually. These details will be thoroughly described by the instructor. Business Security Review: The semester-long project in this class will require you to work with 3 or 4 of your classmates on an Information Security Review of a business or organization. This will consist of both a written report and a class presentation detailing the various policies and procedures your chosen business has instituted with regard to safeguarding its information, information systems, and computer networks. There will be two deliverables due over the course of the semester. More information on this in week 2! Extra Credit: There may be an opportunity to earn extra points through your participation in various research projects throughout the semester. These projects may or may not come about, so I cannot guarantee this will happen. You will need to be in class to take part. Academic Dishonesty: I will enforce university regulations regarding the MSU student honor code to their fullest. The code states “As a Mississippi State University student I will conduct myself with honor and integrity at all times. I will not lie, cheat, or steal, nor will I accept the actions of those who do.” Information is also available at this link: http://students.msstate.edu/honorcode You will have to sign a copy of the honor code before accessing the first course assignment, and you will sign the honor code again before every exam. Students with Disabilities: I am committed to providing assistance to help you be successful in this course. Reasonable accommodations are available for students with a documented disability. Please visit the Disability Support Services (DSS) during the first two weeks of every semester to seek information or to qualify for accommodations. All accommodations MUST be approved through the DSS (01 Montgomery Hall). Call (662) 325-3335 to make an appointment with a disability counselor. Changes to the Syllabus: Any changes will be announced during class and posted on the course website. Please contact me for any clarifications. Class Schedule (subject to change) Date Jan 12 Jan 14 Topic M W Book Chapter Course Intro Accountability and Access Control W Jan 26 M Jan 28 W Feb 2 M Feb 4 Feb 9 M W Attacks and Monitoring CISSP Chapter 2 Security Project: Groups Finalized ISO Model CISSP Chapter 3 Assignment 2: Password Cracking Security Project: Milestone 1 Communications Security CISSP Chapter 4 Assignment 3: Network Address Translation Feb 11 W Feb 16 M Security Management Feb 18 W Feb 23 M Feb 25 W Mar 2 M Mar 4 W Administrative Management Mar 9 M Mar 11 W Mar 16 M Mar 18 W Mar 23 M Mar 25 W CISSP Chapter 5 Assignment 4: Wardriving Physical Security CISSP Chapter 13 *** Midterm Exam #1 *** CISSP Chapter 19 Data and Application Security CISSP Chapter 7 Malicious Code and Application Attacks Asset Value, Policies, and Roles Cryptography CISSP Chapter 8 CISSP Chapter 6 CISSP Chapter 9 CISSP Chapter 10 *** Midterm Exam #2 *** Auditing and Monitoring CISSP Chapter 14 Business Continuity / Disaster Recovery CISSP Chaps 15-16 Apr 8 W Apr 13 M Law and Investigations Apr 15 W Apr 20 M Apr 22 W Apr 27 M W F Security Project: Milestone 2 *** Spring Break – No Class *** Mar 30 M Apr 1 W Apr 6 M Apr 29 May 1 Assignment 1: Sign up for Misweb *** MLK Day – No Class *** Jan 19 M Jan 21 CISSP Chapter 1 Milestone and/or Assignment Due Incidents and Ethics Social Engineering CISSP Chapter 17 Assignment 5: Decryption using GnuPG Assignment 6: Securing E-mail using GnuPG Assignment 7: Internet Speed Test CISSP Chapter 18 UPDATED *** Group Presentations *** UPDATED *** Group Presentations *** Assignment 8: Browser Privacy *** Midterm Exam #3 (aka Final Exam) *** 12:00 – 3 PM