Learning Outcomes
Knowledge: Every computing system controls the access to its resources, which include sensitive data. To this end, each system has protects the data and controls the access to the parts which manage the protection. The root cause of all problems related to a system's security is the software. Malicious intruders exploit security holes and vulnerabilities, which are the result of bad design and bad implementation of software. In this course, we provide an holistic approach to the most important problems of software security and to the security mechanisms of computing systems.
Course Content (Syllabus)
Threats, vulnerabilities, and risks. Attacks and countermeasures. IoT attacks. Secure design. The secure IoT system implementation lifecycle. Cryptography and its role in securing the IoT. Cryptographic module principles. Cryptographic key management fundamentals. Cryptographic controls for IoT protocols. Introduction to identity and access management (IAM) for the IoT - The identity lifecycle, Authentication credentials, IoT IAM infrastructure, Authorisation and access control. Privacy challenges introduced by the IoT. Performing an IoT Privacy Impact Assessment. Privacy by Design principles. Cloud Security for the IoT.
Keywords
Threats, vulnerabilities and attacks, Security by Design, Cryptography, Access control, Authentication, Privacy, Cloud security
Additional bibliography for study
- A. Rashid, H. Chivers, E. Lupu, A. Martin, S. Schneider, "CyBOK - The Cyber Security Body of Knowledge", 2021