Summer 2014 3 Credit Hours



Similar documents
USF Sarasota-Manatee College of Business Information Technology CGS Credit Hours Computers in Business Fall 2015, USF Sarasota-Manatee

University of South Florida Sarasota/Manatee Course Syllabus Fall 2015 (updated )

USF Sarasota-Manatee CIS 4368 Database Security and Auditing Summer Office Hours: By Appointment

CGS Web Development: JavaScript

CIS 523/423 Disaster Recovery Business Continuity

MAN 4802 Entrepreneurship/Small Business Management Online Fall 2013

College of Public Health University of South Florida. Department of Environmental and Occupational Health. Syllabus Page 1

University of South Florida Sarasota-Manatee Course Syllabus Forensic Accounting and Fraud Examination ACG 4931 Spring 2015

CIS 4204 Ethical Hacking Fall, 2014

ISM 4113: SYSTEMS ANALYSIS & DESIGN

MAN 4802 Entrepreneurship/Small Business Management Online. Fall 2012

University of South Florida Sarasota-Manatee COURSE SYLLABUS

University of South Florida Sarasota-Manatee Course Syllabus Forensic Accounting and Fraud Examination ACG 4931 Fall 2015

CIS 3615 Secure Software Development

Entrepreneurship & Small Business Management. USF College of Business. MAN 4802 Fall 2014 Room: BSN 124. Instructor: Jennie Jolly

CIS 4203 IT Forensics & Investigations Summer C

FLORIDA INTERNATIONAL UNIVERSITY

Instructor: Michael A. Gillespie, Ph.D. Office Hours: M, W 11:00 to 12:00

EME6055: Current Trends in Instructional Technology

CTS 4348 Linux Administration Spring 2014

EDF 3214: Human Development and Learning Section 901 Meeting Time: Mondays from 5-9 Room: CPR 256

MIS 7381 Syllabus_Spring 2016_Cooper.doc 1 02/08/16 2:44 PM

SPRING 2013 BUSINESS COMMUNICATIONS Syllabus

Systems and Internet Marketing Syllabus Spring 2011 Department of Management, Marketing and International Business

COURSE SYLLABUS FIREWALLS & NETWORK SECURITY. ITSY-2301 Number Lecture - Lab - Credit. ITSY-1342 Prerequisites. April 16, 2015 Revision Date

MIS 4336 Networks and Data Communication. Spring 2016

ISM 4210: DATABASE MANAGEMENT

Social Gerontology SOC 210 Fall Professor: Jamie Chapman, PhD Candidate Class Location: Patterson Hall 205

JOU4700: Problems and Ethics in Journalism Course Syllabus, Spring 2015 Mondays, 3-6 p.m. Florida Gym, Room 260

PROJECT MANAGEMENT MAN 4930

ISM and 05D, Online Class Business Processes and Information Technology SYLLABUS Fall 2015

Imperial Valley College Course Syllabus - Elementary Differential Equations Math 220

Systems and Internet Marketing Syllabus Fall 2012 Department of Management, Marketing and International Business

SYLLABUS Human Resource Management MGMT 3241 Section 001 Spring 2006, MW 3:00-4:20 Friday 9

This four (4) credit hour. Students will explore tools and techniques used penetrate, exploit and infiltrate data from computers and networks.

Investment Management Course

BCIS Business Computer Applications D10

SYLLABUS FALL 2015 PHI 3640 Environmental Ethics (A 100% Online Class) 3 credits (Subject to Revision and Canvas Posting with Notice)

BCM :00-12:15 p.m. 1:30-3:35 p.m. Wednesday 10:00-12:00 noon

Human Resource Management Political Science (POLS) 543 Spring 2013 Course Meets: Tuesday and Thursday 11:00-12:15 p.m. Faner 3075

MIS Systems Analysis & Design

ABNORMAL PSYCHOLOGY (PSYCH 238) Psychology Building, Rm.31 Spring, 2010: Section K. Tues, Thurs 1:45-2:45pm and by appointment (schedule via )

ERP 5210 Performance Dashboards, Scorecard, and Data Visualization Course Syllabus Spring 2015

COMP252: Systems Administration and Networking Online SYLLABUS COURSE DESCRIPTION OBJECTIVES

BCIS Business Computer Applications - Online

Florida Gulf Coast University Lutgert College of Business Marketing Department MAR3503 Consumer Behavior Spring 2015

Gordon College ECB 362 Cost Accounting Online Summer Flexibility with Responsibility

Research Methods in Psychology

CJ 4480 Digital Forensics II Syllabus - Term

COMM Interpersonal Communication Course Syllabus Fall 2013

Small Business Management BUSG 2309 Course Syllabus

Blinn College Course Syllabus

Course Syllabus - IST 454 Computer and Cyber Forensics General Course Information

BACHELOR OF SCIENCE IN HOSPITALITY MANAGEMENT MISSION STATEMENT

ENC2210 Technical writing for health science majors. Course Description:

Florida International University College of Nursing and Health Sciences Health Services Administration Policies and Procedures

16-week online course COURSE DESCRIPTION: Business 001 COURSE TEXT: ISBN COURSE OBJECTIVES

CE 460 Course Syllabus

PSYCH 3510: Introduction to Clinical Psychology Fall 2013 MWF 2:00pm-2:50pm Geology 108

MATH 245 COLLEGE ALGEBRA Section :55 1:30

Management 352: Human Resource Management Spring 2015 Syllabus

PHIL 1010 Georgia State University Fall 2008 Critical Thinking Department of Philosophy George Rainbolt

MGMT 280 Impact Investing Ed Quevedo

ACCT 510 Forensic Accounting Spring 2015 T/R 10:50 12:05 PM, Tate 304

Human Development and Learning in Social and Educational Contexts (EDP 201) Spring 2012 Syllabus

(Texas Tech) AND (personal)

CIS 160 ST: Web Design and Technology

This course is 100% online via Canvas

GEB Writing in Business Fall 2015

CE 460 Course Syllabus

INFO & 090 Business Data Communications and Information Security Fall 2014

School of Business and Nonprofit Management Course Syllabus

College of Education Graduate Departmental Course Syllabus Summer as of 5/6/2014

Political Science Department AMERICAN NATIONAL GOVERNMENT. Political Science 1113 CRN# Spring Online Class

STA 4442 INTRODUCTION TO PROBABILITY FALL 2012

COURSE SYLLABUS. Office Hours: MWF 08:30am-09:55am or by appointment, DAV 238

AEB 3122 Financial Planning for the Agribusiness 3 Credits Fall 2012

COURSE SYLLABUS COURSE REQUIREMENTS

CIT 212 Microsoft Networking II Windows Server 2012 R2 Administration Fall 2015

IST359 - INTRODUCTION TO DATABASE MANAGEMENT SYSTEMS

AEC 3073 INTERCULTURAL COMMUNICATION Ms. Mary Rodriguez

BUS 3525 Strategic Management Online

General Psychology. Course Syllabus

Principles of Financial Accounting Bus 210

Course Code:MGT520 Course Name: Organizational Behavior Module II, Academic Year:

Introduction to Physics I (PHYS ) Fall Semester 2012

MGT 3303 Human Resource Management

GOVT 2306 Texas State Government (Online) Course Syllabus: December Intersession

BCM 247 BUSINESS COMMUNICATION Course Syllabus Fall 2012

Department of Criminal Justice CRJ 325 Incident Management and Planning

Psychology 103 Your ticket # Spring 2013 Cerritos Community College

Transcription:

College of Hospitality and Technology Leadership CIS 4365 Computer Security Policies & Disaster Preparedness Summer 2014 3 Credit Hours University of South Florida Sarasota/Manatee 8350 North Tamiami Trail, Sarasota, FL 34243 Telephone: 941-359-4200 Fax: 941-359-4367

University of South Florida Sarasota/Manatee Course Syllabus Summer 2014 Course Number: CIS 4365 Classroom: Online using Elluminate Class Time: Mondays & Wednesdays, 1:00 3:00 pm Course Name: Computer Security Policies and Disaster Preparedness Course Description: Instructor: When an organization is interrupted by disasters, accidents, or natural events, a loss of data and/or productivity occurs. The extent to which this loss affects the health of the organization is determined by how prepared the organization is for dealing with these disruptions. Organizations impacted by this loss span the gamut, including but not limited to agencies, industries, corporations, hospitals and universities. This course prepares students to understand, devise, and implement IT policies, procedures, and continuity plans, uniquely tailored to an organization s specific needs. Dr. S. Lodwig Phone: 941 966 1260 e mail: slodwig@sar.usf.edu Office Hours: Required Materials: Meetings can be held over the phone, Elluminate, Skype or face to face at school by appointment. For a fast response, best way to contact me is via email. Please use your Canavs account to send course related email. Otherwise, it may get buried in the over a 100 emails I receive daily. Principles of Incident Response and Disaster Recovery, 2nd Edition Michael E. Whitman Ph. D., CISM, CISSP; Herbert J. Mattord MBA, CISM, CISSP Thomson Course Technology, ISBN10: 1 111 13805 2 ISBN13: 978 1 111 13805 9 2

Suggested Reference Materials: Michael Erbschloe, Guide to Disaster Recovery. Thomson Course Technology, 2003 ISBN 0 619 131225. Michael Wallace and Lawrence Webber, The Disaster Recovery handbook: A Step by step Plan to Ensure Business Continuity and Protect Vital Operations, Facilities, and Assets. AMACOM, 2004 ISBN 0 8144 7240 0. James C. Barnes, Guide to Business Continuity Planning. Wiley 2001 ISBN 0471530158. Jon William Toigo and Margaret Romao Toigo, Disaster Recovery Planning: Preparing for the Unthinkable, 3 rd edition. Pearson Education, 2002 ISBN 0130462829. Andrew McCrackan, Practical Guide to Business Continuity Assurance. Artech House, 2004 ISBN 1580539270. Charlotte J. Hiatt, A Primer for Disaster Recovery Planning in an IT Environment. Idea Group, 2000 ISBN 1878289810. James F. Ransome and John W. Rittinghouse, Business Continuity and Disaster recovery for InfoSec Managers. Elsevier, 2005 ISBN 1555583393. Other www.disaster recovery guide.com Supplementary www.drii.org Materials: www.disasterrecoveryworld.com Lots of additional material will be shared in class Prerequisites: CIS 3360 Course Goals: This course provides the student with a foundation in disaster recovery and continuity principles, including preparation of a disaster recovery/continuity plan, assessment of the risks facing the enterprise, development of policies and procedures, understanding the roles and relationships of the various players in an organization, implementation of the plan, testing and rehearsing of the plan, and actually recovering from a disaster, ensuring systems and data are restored and the organization up and running as quickly as possible. Performance Objectives: Two key goals of the course, encompassed in a Term Project (done in small teams), include: 1. Understanding the security implications of disaster recovery and business continuity Students will be required to submit a written plan of disaster recovery and business continuity including the following topics: risk assessment, downtime estimate, criticality prioritization, backup and fault tolerance, quality of analysis and planning of disaster recovery and business continuity. Students can choose a real business to develop this plan for. 2. Understand the concept and uses of security policies and procedures Students will be required to submit a written short policies and procedures on password and account management, privilege management, users education, code of ethics, media controls, disposal/destruction and incident response, quality of analysis and planning on disaster recovery and business continuity. On completion of this course students will be able to: Describe how an organization develops a disaster recovery and continuity 3

Instructional Methodology: Attendance Policy: Students with Disabilities: planning philosophy as well as a disaster recovery/continuity plan. Explain how to organize the disaster planning team. State the fundamental building blocks of planning. Describe how to prioritize the activities most critical to the organization Show how the planning team develops recovery procedures for each facility the organization operates. List the various agencies an organization needs to work with to recover from a disaster, including law enforcement, emergency services, utilities, partner organizations, and suppliers. Distinguish disasters that can result from cyber attacks and hackers, rather than from natural occurrences or accidents. Explain how to protect special assets (hazardous materials, controlled substances, historic documents, trade secrets) in the event of a disaster. Describe how an organization puts its plan into effect, including development of an implementation plan, assessing the value of mitigation steps, assigning responsibilities for implementation, establishing an implementation schedule, and training employees. Explain how to develop testing scenarios to evaluate how well disaster recovery plans and procedures actually work. Describe how to transition into maintenance mode after the plan is implemented. Define how to capture the knowledge and experience gained during an actual disaster. Student and instructor presentations, demonstrations, discussions, and handson use of computers to complete exercises and assignments. A Term project will be assigned to be done in teams. Since the class is being offered in both a synchronous and asynchronous mode, class attendance is optional. However, you are very strongly encouraged to attend each class listening to a recording is just not the same as participating in an interactive class. Additionally, the course moves through the material at a rapid pace, and each topic builds on the ones that preceded it. Getting behind in an asynchronous mode is easy, and catching up is difficult. Attempting to cram the material will surely lead to failure to adequately grasp it. Some assignments and the term project are group based and attending the class facilitates these group activities. Every team member is expected to pull their weight and anyone who does not, will receive a lesser grade than their team mates. Some assignments require in class presentations. Hence, all in all, you should make every attempt to attend the class in person. Students are responsible for submitting assignments on time, whether these be individual ones or group based ones. Late assignments will not be accepted. This rule will be strictly enforced given the short duration of the semester and the vast content to be covered. Students with disabilities are responsible for registering with the Office of Student Disabilities Services in order to receive special accommodations and services. Please notify the instructor during the first week of classes if a 4

Religious Observances: Performance Evaluation and Grading reasonable accommodation for a disability is needed for this course. A letter from the USF Disabilities Office must accompany this request. Students who anticipate the necessity of being absent from class due to the observation of major religious holidays must provide written notice of the date(s) to the instructor by the second class meeting. Student performance will be evaluated based on class attendance and participation, one exam, a few quizzes, exercises and assignments. Each unexcused absence will result in an automatic deduction of 2 percentage points from the Class Attendance grade. The relative weights for each of these components in determining the final grade are as follows: Class Participation 10% Exams (quizzes/final) 20% Exercises and Assignments 40% Term Project 30% Total 100% A grade will be determined based on the total of possible points earned, as follows: A 90 100; B 80 89; C 70 79; D 60 69; F 0 59. Extra Credit: Some assignments, exams and other activities may have an extra credit component associated with them. Points earned in this manner will be not be included in the assignment or exam grade or in the final course average These will be considered after course letter grades have been tentatively assigned. Extra credit may result in an increase in your final letter grade, especially in borderline situations, and will never reduce your grade. For this reason, you should take full advantage of extra credit opportunities. Incomplete Grade: An Incomplete grade in the course is reserved for those with good reason for having missed a small amount of work, and are agreed to by the student and instructor during the course, as circumstances require. Otherwise, exams not taken or assignments not turned in will receive a zero for that grade, and the course grade assigned accordingly. Please note, it is the student s responsibility to ensure the work is completed before the end of the following semester and the Incomplete changed to a regular grade. If this is not done before the end of the following semester, the Incomplete automatically becomes an F! STATEMENT ON ACADEMIC HONESTY The instructor of this course trusts that all students behave in strict compliance with accepted standards of academic honesty. A conscious effort is made to ensure that grading standards are fair, and that anyone who makes an honest and consistent attempt to do well in the course will succeed, as, by this time in your degree program, it is expected that you are capable of doing the work. There will be no tolerance for anyone who attempts to "succeed" by dishonest routes. Academic honesty includes, but is not limited to: Honesty in taking examinations. 5

Honesty in completing your assignments yourself. There is no objection to some degree of helpful collaboration in completion of assignments; often a rough spot can be overcome with a helpful word. But assignments passed in for grading must be substantially one person's the submitter's work. Please note that in many of the assignments for this course, it will be fairly obvious to the instructor when students have collaborated beyond a reasonable degree (having exactly the same wrong answer, for example, is usually a dead giveaway). Honesty in attributing others' work. In all submitted work, including papers and presentations, ideas, concepts and quotations obtained from other persons' works must be properly attributed. Not doing so constitutes theft of intellectual property. Consequences for violating this trust will be severe. Credit will not be given for any work that does not meet the above criteria. In an extreme violation or repeated violations, a failing grade in the course for reasons of academic dishonesty is an appropriate and reasonable penalty. Academic Dishonesty: In accordance with university guidelines as found in the Student Handbook, anyone found cheating during exams, submitting work that is not theirs, plagiarizing or falsifying work that is submitted to represent work they have done shall receive an F with numerical value of zero on the item submitted, and the F shall be used to determine the final course grade. It is the option of the instructor to assign the student a grade of F or FF (the latter indicating dishonest) in the course. The instructor may use the Turnitin.com software to access potential plagiarism and precise obligation to reference all materials taken from electronic sources. EMERGENCY PROCEDURES In the event of an emergency, it may be necessary for USF to suspend normal operations. During this time, USF may opt to continue delivery of instruction through methods that include but are not limited to: Blackboard, Elluminate, Skype, and email messaging and/or an alternate schedule. It s the responsibility of the student to monitor Blackboard site for each class for course specific communication, and the main USF, College, and department websites, emails, and MoBull messages for important general information. Class Schedule: Week Topics Pre Class Reading* Assignments/Term Project Deliverables Exams/ Due Dates 1 2 3 Contingency Planning Planning for Organizational Readiness Incident Response: Preparation, organization, and Prevention Detection and Decisionmaking Incident Response: Reaction, Recovery and Maintenance Chapters 1 and 2 Chapters 3 and 4 Chapters 5 and 6 Assignment from Chapters 1 & 2 Intro & Planning Policy Statement (reasons, goals, resources) Business Impact Analysis (which systems matter?) May 25th June 1st June 8th 6

Contingency Strategies Disaster Recovery: Chapter 7 Identify Preventive Controls (can you June15th 4 Preparation and Chapter 8 avoid disaster?) Implementation Operation and Maintenance 5 Midterm Exam(online based on chapters 1 5) & catch up Developing Procedures For Special Circumstances Chapter 8 Develop Recovery Strategies Assessing the potential damage or June 29th 6 impact of an incident or emergency and planning emergency response procedures, crisis management, and crisis communication. 7 8 Business Continuity: Preparation and Implementation Operation and Maintenance Crisis Management & Human Factors Chapters 9 and 10 Chapter 11 Exercises from Chapter 8 Restoring the most time sensitive, essential business operations as quickly as possible, including the transfer of business operations and resources from temporary facilities to permanent facilities. Implementing expanded recovery operations for less time sensitive business operations. Implementing the repair or relocation of the primary site of operations and the restoration of normal business operations at the primary site. DEBRIEFING: Reviewing and adjusting disaster recovery plans based on experiences learned. June 29th July 13th Term Project Presentations Debriefing July 17 th Final exam available 9 on CANVAS 7/17 (based on chapters 6 11) 10 Complete Final Exam Midnight July 20th *Chapters assigned each week should be read prior to the class. 7