Information Security Testing and Assessment (5cr)
Code: 5051244-3005
General information
- Enrollment
- 02.12.2024 - 16.01.2025
- Registration for the implementation has ended.
- Timing
- 13.01.2025 - 30.04.2025
- Implementation has ended.
- Number of ECTS credits allocated
- 5 cr
- Local portion
- 5 cr
- Mode of delivery
- Contact learning
- Unit
- Engineering and Business
- Campus
- Kupittaa Campus
- Teaching languages
- English
- Seats
- 10 - 65
- Degree programmes
- Degree Programme in Information and Communications Technology
- Degree Programme in Business Information Technology
- Degree Programme in Information and Communication Technology
- Teachers
- Jani Ekqvist
- Teacher in charge
- Jani Ekqvist
- Groups
- 
                        PTIVIS22TData Networks and Cybersecurity
- 
                        PTIETS22dncsPTIETS22 Data Networks and Cybersecurity
- Course
- 5051244
Realization has 26 reservations. Total duration of reservations is 78 h 0 min.
| Time | Topic | Location | 
|---|---|---|
| Thu 16.01.2025  time 10:00 - 12:00 (2 h 0 min) | Introductory Lecture, Information Security Testing and Assessment 5051244-3005 | ICT_C1035_Delta
                                    DELTA | 
| Mon 20.01.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 23.01.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 27.01.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 30.01.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 06.02.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 06.02.2025  time 16:00 - 19:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 10.02.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 13.02.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 24.02.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 27.02.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 03.03.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 06.03.2025  time 08:00 - 11:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 10.03.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 13.03.2025  time 08:00 - 11:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 17.03.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 20.03.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 24.03.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 27.03.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 31.03.2025  time 10:00 - 14:00 (4 h 0 min) | Hackathon, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 07.04.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 10.04.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Mon 14.04.2025  time 13:00 - 16:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 17.04.2025  time 09:00 - 12:00 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 24.04.2025  time 08:45 - 11:45 (3 h 0 min) | Laboratory work, group 2, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
| Thu 24.04.2025  time 14:00 - 17:00 (3 h 0 min) | Laboratory work, group 1, Information Security Testing and Assessment 5051244-3005 | ICT_C3036
                                    Cyberlab / BYOD | 
Evaluation scale
H-5
                    
Content scheduling
Course begins with introductory lecture. In laboratory exercises student learns to use the tools of trade. Finally, students perform a penetration testing engagement and report the results.
                    
Objective
After completing the course the student:
 - is able to explain the basic principles of information security testing and assessment
 - can list the phases of information security testing process
 - is able to organize and conduct information security risk testing to an SME sector enterprise or similar size organization
 - can analyse and report the results from information security testing
 - is able to give justified improvement proposals to mitigate information security vulnerabilities
                    
Content
- Social Engineering
- Penetration Testing
- Network Discovery
- Network Service Identification
- Vulnerability Scanning
- Password Cracking
                    
Materials
We are using the TryHackMe.com training platform in addition to ItsLearning. Licenses for the duration of the course will be provided for students taking the course for the first time. Student is responsible for acquiring any additional licenses if course is not completed in time, or on any subsequent implementations.
                    
Exam schedules
Mandatory Practical exam is early April, with re-take chance in April.
                    
Completion alternatives
-
                    
Student workload
Lectures 8h
Laboratory assignments 35h
Hackathon 8h
Exam and preparations 9h
Testing project 75h
                    
Evaluation methods and criteria
Project report determines the grade. At least 3 successfully tested machines must be reported following the reporting requirements to get 1. Each successfully tested and reported machine above that will increase grade by 1. Incomplete reporting will lower the grade.
Exam is mandatory to pass. Getting 5 in exam increases overall grade by 1. 
Attendance in Hackathon is mandatory to pass the course.
Laboratory assignments: returning at least 90% of the graded assignments by deadline will increase overall grade by 1.
                    
Failed (0)
Student is unable to perform and report a penetration testing engagement independently.
                    
Assessment criteria, satisfactory (1-2)
Student understands the basics of penetration testing and is able to perform a penetration test against a web application independently. Student can write an understandable and actionable report about the test results.
                    
Assessment criteria, good (3-4)
Student has a good grasp of information security testing methodologies and tools. Student can independently test various types of internet connected applications. Student can write an understandable and actionable report about the test results that contains guidance for both the management and the developers responsible for the application.
                    
Assessment criteria, excellent (5)
Student has knowledge and is able to select the best suited tool and methodology for the engagement. Student can independently test most types of internet connected applications. Student can write a clear, concise and actionable report about the test results that effectively guides management decisions and provides the software developers with detailed guidance on both fixing to found issues and methods for avoiding similar issues in the future.
                    
Qualifications
Courses Internet Networks and Security and Linux and Virtualization
                    
Further information
All communication will be through ItsLearning.