Information Security Risk Management (5 cr)
Code: 3011369-3008
General information
- Enrollment
- 02.06.2025 - 31.08.2025
- Registration for the implementation has begun.
- Timing
- 01.09.2025 - 21.12.2025
- The implementation has not yet started.
- Number of ECTS credits allocated
- 5 cr
- Local portion
- 5 cr
- Mode of delivery
- Contact learning
- Unit
- Engineering and Business
- Campus
- Kupittaa Campus
- Teaching languages
- English
- Seats
- 30 - 60
- Degree programmes
- Degree Programme in Information and Communications Technology
- Degree Programme in Business Information Technology
- Degree Programme in Information and Communication Technology
- Teachers
- Pia Satopää
- Teacher in charge
- Pia Satopää
- Groups
-
PTIVIS23TData Networks and Cybersecurity
-
PTIETS23dncsData Networks and Cybersecurity
-
Vaihto2526dncsData Networks and Cybersecurity
- Course
- 3011369
Realization has 18 reservations. Total duration of reservations is 36 h 0 min.
Time | Topic | Location |
---|---|---|
Mon 01.09.2025 time 12:00 - 14:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1027_Lambda
LAMBDA
|
Wed 03.09.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
|
Mon 08.09.2025 time 12:00 - 14:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1027_Lambda
LAMBDA
|
Wed 10.09.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
|
Mon 15.09.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
|
Thu 18.09.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1027_Lambda
LAMBDA
|
Wed 24.09.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
|
Thu 25.09.2025 time 15:00 - 17:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1042_Myy
MYY
|
Wed 01.10.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
|
Thu 02.10.2025 time 13:00 - 15:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1027_Lambda
LAMBDA
|
Wed 08.10.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
|
Thu 09.10.2025 time 14:00 - 16:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1042_Myy
MYY
|
Wed 22.10.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
|
Thu 23.10.2025 time 12:00 - 14:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
LEM_A173_Lemminkäinen
Lemminkäinen
|
Wed 29.10.2025 time 08:00 - 10:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
EDU_1002
Moriaberg Esitystila byod
|
Mon 03.11.2025 time 12:00 - 14:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1027_Lambda
LAMBDA
|
Mon 10.11.2025 time 12:00 - 14:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1027_Lambda
LAMBDA
|
Mon 17.11.2025 time 12:00 - 14:00 (2 h 0 min) |
Information Security Risk Management 3011369-3008 |
ICT_C1027_Lambda
LAMBDA
|
Evaluation scale
H-5
Content scheduling
After completing the course the student can:
- explain basic principles of ISO/IEC27005:2008 -standard based information security risk assessment and risk management
- explain the basic principles of information security risk assessment and risk management
- list the phases of information security risk management process
- classify information security risks by applying different approaches
- give examples of different information security risk assessment methods
- organize and conduct information security risk assessment to an SME sector enterprise or similar size organization
- analyze the results of information security risk assessment
- give justified improvement proposals to mitigate information security risks.
- Understands information security risk management as part of continuity planning and preparedness
Objective
After completing the course the student can:
- explain the basic principles of information security risk assessment and risk management
- list the phases of information security risk management process
- classify information security risks by applying different approaches
- give examples of different information security risk assessment methods
- organize and conduct information security risk assessment to an SME sector enterprise or similar size organization
- analyze the results of information security risk assessment
- give justified improvement proposals to mitigate information security risks.
Content
- The basic principles of information security risk assessment and risk management
- Information security risk management standard ISO/IEC 27005:2008
- Information security risk assessment methods and best practices
- Practical work
Materials
Material will be published in Itslearning.
Teaching methods
- Lectures, assignments and practical work
Exam schedules
Course has an exam.
Pedagogic approaches and sustainable development
Students work in groups using a problem-based approach according to the constructivist model, acting as active producers of knowledge by applying what they have learned in theory to practical examples
Completion alternatives
An alternative method of completion must be agreed separately with the teacher
Student workload
Lectures
Assignments and practical work/group work
Evaluation methods and criteria
The grade is based on the group assignment, peer assessment, exam, attendance, as well as group and individual self-assessment. The assessment criteria are presented at the beginning of the course and may differ from those outlined here.
The group assignment carries the highest weight in the evaluation. More than 50% absence from in-person classes will result in failing the course. Absences must be discussed with the instructor separately.
Failed (0)
<50% of assignment and exam points.
More than 50% absence from in-person classes
Assessment criteria, satisfactory (1-2)
The group assignment is weak in both quality and content, and at least 50% of the points are achieved in the exam.
Assessment criteria, good (3-4)
The group assignment is moderate or good in quality and content, the student has completed their share of the group work, and at least 70% of the points are achieved in the exam.
Assessment criteria, excellent (5)
The group assignment is excellent in both quality and content, the student has completed their share of the group work with excellence according to peer assessment, and at least 90% of the points are achieved in the exam.
Further information
It´s Learning