IY2S402 - Information Assurance and Compliance 01 Sep 2024 - 31 Jul 2030 | Version 0

Associated Module Information

Module Code: IY2S402
Module Title: Information Assurance and Compliance
Faculty: Faculty of Computing, Engineering and Science
Faculty Group: Cyber Security
Faculty Sub Group: Cyber Security
Module Leader: Christopher Tubb
Module Team: Ashley Nute, Barbara Hayman, David Reed, Gaynor Davies, Robert James, Stefanie Allaway
First Intended Intake: SEP 2024 Final Year of Intake: 2029
Date Closed:
Credit Value: 20 Credit Level: 5
Language: English
Percentage of Module Taught in Welsh: 0
Equivalent Module:
HECOS codes: 100376 - computer and information security
HECOS Code Weighting: 100

Document Version Information

Version 0
Valid From 01 Sep 2024
Valid To 31 Jul 2030

Module Aims

To develop an ability to evaluate and analyse the underlying principles of strategic risk management, governance, and compliance strategies in order to manage a corporate information security governance infrastructure at the strategic and tactical levels. 

To provide knowledge of the tools, techniques, frameworks, and legislation associated with regulatory governance and compliance. 

Content Summary

  • Introduction to IT Governance and risk management. 

  • Audit process & project management. 

  • Quality assurance & Governance/Management of IT/GDPR. 

  • legislation – GDPR etc. Introduction to Privacy for the IT professional (Privacy/Privacy Notice, Security & Data Governance/Data Life Cycle & Protection) 

  • IT Related Frameworks (ISO 27001, 27002, ITIL, COBIT, NIST?etc.) & Organisational Structure. 

  • System Performance Management, Identity and Access Management & Enterprise Architecture. 

  • Change/patch/release/incident Management 

  • Incident Analysis and Response 

Learning and Teaching Methods

Activity Type Hours
Lecture 24
Seminars 12
Practical Classes and Workshops 12
Independent Study 102
Direct Study (including online independent learning) 40
Formative Assessment (independent) 10
Total Hours Selected 200

Learning Outcomes

# Learning Outcome
LO1 To evaluate and analyse the tools, techniques, principles, and practices associated with Cyber Governance and Compliance.
LO2 To evaluate corporate governance strategies for cyber security and to mitigate risk.

Module Requisites

N/A

Assessment Criteria

Assessment Category Assessment Type Description Duration Word Count Weight (%) Best of? Pass Mark
Asynchronous Assessment Essay 1 A written composition with a specified word length that, typically, on the basis of existing literature, proceeds to sustain a coherent argument 0 2000 40 No 40
Synchronous Onsite Oral Assessment Oral Assessment (Internally assessed, Onsite) 1 A prepared oral presentation by a candidate before assessor(s) and possibly peers, where knowledge, technical content, ability to answer questions and presentational skills are assessed. 15 N/A 60 No 40

Assessment Matrix

Assessment Type Learning Outcomes
LO1 LO2
Essay 1
Oral Assessment (Internally assessed, Onsite) 1

Reading List

Calder, A. (2019) Implementing Information Security Based on ISO27001/2. Cambridgeshire: IT Governance Publishing. 

Blokdyk, G. (2018), ISO 31000: A complete guide 

Wens, C. (2019), ISO 27001 Handbook, independently published. 

Wright, C. (2016), Fundamentals of Information Risk Management Auditing, Ely, IT Governance Publishing. 

BS ISO/IEC 27001: Information technology - Security techniques. Information security management systems. ISO. British Standards Institute. 

BS ISO/IEC 27002: Information technology - Security techniques. Code of practice for information security management. ISO. British Standards Institute. 

Cascarino, R. (2012), Auditors Guide to IT Auditing, (2nd Edition), New Jersey .