IY3S669 - Security and System Administration 01 Sep 2021 - 31 Aug 2026 | Version 4

Associated Module Information

Module Code: IY3S669
Module Title: Security and System Administration
Faculty: Faculty of Computing, Engineering and Science
Faculty Group: Computing and Mathematical Sciences
Faculty Sub Group: Computer Science
Module Leader: Mamoun Qasem, Ian Fitzell
Module Team: Andrew Bellamy, Ramadhan Rajab
First Intended Intake: SEP 2019 Final Year of Intake:
Date Closed:
Credit Value: 20 Credit Level: 6
Language: English
Percentage of Module Taught in Welsh: 0
Equivalent Module:
HECOS codes: 100376 - computer and information security
HECOS Code Weighting: 100

Document Version Information

Version 4
Valid From 01 Sep 2021
Valid To 31 Aug 2026

Module Aims

To develop a detailed knowledge of the processes, tools and techniques inherent with the administration, management and governance associated with securing computer systems.

Content Summary

Identity and Access Management
• Using Tools to access your Network
• Troubleshooting common access issues
• Security Technologies
o Intrusion Detection Systems (IDS)
o Antimalware
o Firewalls
• Key Concepts
o Identification, authentication and authorisation
o Multifactor and biometrics
o Potential Authentication Access Issues, e.g.
? Password Authentication Protocol (PAP)
? Challenge Hash Authentication Protocol (CHAP)
o Lightweight Directory Access Protocol (LDAP) and Active Directory (AD)
o Single Sign on Technologies, e.g. Kerberos
o Install and Configure Identity and Access Services

Monitoring and Diagnosing the Networks
• Frameworks, Best Practices, and Configuration Guides
• Secure Network Architecture Concepts
o Log Analysis and Event Sub-Systems Administration (Windows and UNIX)
o System Security Visualisation
o Scripting and Regular Expressions
o Network Defence in Depth
• Secure System Design
o Hardware Firmware Software
o Secure Staging and Deployment Concepts

Securing the Cloud and Virtualisation
• Understanding Cloud Computing Technologies
o Private and Public Cloud
• Understanding Virtualisation Technologies
o Hypervisor
o Virtualisation Specific Security Concerns
• Cloud Storage
• Security as a Service

Handling Malware
• Malware Administration
• Anti-malware application deployment and management
• Process and Memory Management

Learning and Teaching Methods

Activity Type Hours
Lecture 24
Practical classes and workshops 16
Independent Study 88
Directed Study 72
Total Hours Selected 200

Learning Outcomes

# Learning Outcome
LO1 To administer and secure a variety of computer/network devices at the network and operating systems level.
LO2 To configure and audit a variety of devices and applications.

Module Requisites

N/A

Assessment Criteria

Assessment Category Assessment Type Description Duration Word Count Weight (%) Best of? Pass Mark
Asynchronous Assessment Report 1 Given a scenario generate a security and threat analysis report with recommendations 0 2000 50 No 40
Asynchronous Assessment Report 2 A study that reflects the latest topics within the subject area of the module. As the subject is fast moving, this description best fits its aims 0 2000 50 No 40

Assessment Matrix

Assessment Type Learning Outcomes
LO1 LO2
Report 1
Report 2

Reading List

Albing, C., Vossen, J. P., Newham, C., (2007) Bash Cookbook, O'Reilly

Blyth A., & Kovacich G., (2007) Information Assurance, Springer.

Davis, M., Bodmer, S., and LeMasters A., (2016), Hacking Exposed: Malware & Rootkits Secrets & Solutions [2nd Ed], McGraw-Hill Osborne Media

Fry, Chris and Nystorm, Martin. (2009), Security Monitoring, (1st Ed.), O'Reilly Media, Inc.

Krutz, R.L., and Vines, R. D., (2010), Cloud Security: A Comprehensive Guide to Secure Cloud Computing [Paperback], Wiley

Ligh, M., Richard, M., Adair, S., and Hartstein, B., (2010), Malware Analyst's Cookbook and DVD: Tools and Techniques for Fighting Malicious Code [Paperback], Wiley

McNab, C., (2016) Network Security Assessment Know Your Network, (3rd Ed.),O'Reilly

Microsoft, (current) Windows (current) Resource Kit, Microsoft Press

Peikari, Cyrus and Chuvakin, Anton. (2004), Security Warrior, O'Reilly Media, Inc.

Winkler, V.J.R., (2011), Securing the Cloud: Cloud Computer Security Techniques and Tactics, Syngress

Kim, P. (2015) The Hacker Playbook 2: Practical Guide To Penetration Testing, CreateSpace Independent Publishing Platform

Journals:

IEEE Security and Privacy

On-line sources:

Computer Networks, Elsevier B.V.

Computers & Security, Elsevier Ltd.

Wu, C. and Irwin, D. (2013), Introduction to Computer Networks and Cybersecurity, CRC Press