Security in Networks
These subjects provide students with extensive
knowledge on basic security concepts, applicable to
a wide range of fields, and allow them to manage
and administrate the security aspects of information
systems. The main purposes of this subject are the
following:
Become familiar with the security process
Identify the risks for information systems
Know the security mechanisms with which to
equip an information system
Understand the fundamental concepts of
cryptography
Understand the nature, definition, and
application of a security policy
After completing this subject, the student will
have of a series of competences with which to
manage and administrate the security of information
systems. These competences can be divided into
three large groups:
Competences related to conceptual capacity:
Summarize the foundations of
cryptosystems
Know the legal aspects of information
systems security
Define the risks and vulnerabilities of an
information system
Analyse new advances in security and
their repercussions
Competences related to procedural capacities:
Use security tools
Organize the security of an information
system
Express clearly and effectively the need
for security measures and their
implantation, advantages, and
disadvantages
Competences related to behavioural capacities:
Assume the existence of vulnerabilities in
information systems and minimize them
Assess a system’s security in a critical
and objective manner
Collaborate with other professionals (such
as system administrators, networks,
databases, applications, etc.) in launching
and maintaining security measures.
These competences will allow students to carry
out their work in the systems security field. They
will be able to design, implant, and evaluate the
security mechanisms, the incident detection
mechanisms, and the security policy of an
information system.
3 TEACHING METHODOLOGY
The subject is based on three elements: theoretical
classes, practical classes, and practical exercises.
During the theoretical classes, the fundamental
concepts of the subject are introduced so as to allow
the student to study the proposed matter in depth. At
this point, the teaching staff plays an essential role,
but the students are also encouraged to participate
actively and this participation will be evaluated.
Students receive the teaching material and a
selection of bibliographical references, which
enable them to prepare the classes in advance or
focus on any given aspect. They may be exposed to
written tests based on brief theoretical questions or
on solving small problems, in order to check their
level of assimilation of the concepts that were
explained during class or analysed individually.
These tests have a duration of approximately 30
minutes and are corrected and commented in class.
The practical classes are dedicated partly to the
application of the exposed theoretical concepts to a
practical case. During these classes, the students
play a more relevant role; the professor merely
presents the case and provides an individualized (or
generalized, if relevant) support in case of doubt.
The practical sessions take place individually (or
in groups of two persons), except for one of the
classes which requires 2 or 3 sessions with groups of
4 to 6 persons. This particular class consists in a
collaborative learning experience in which the group
works on a previously indicated and structured
theme (e.g. the application of security policy to a
concrete case). The group indicates one person
responsible for each part of the work; the persons
responsible for the same part work together and
explain what they do to the rest of their group, so
that in the end all the components of one group have
acquired knowledge on all the parts. In order to
stimulate the explanation of concepts between the
members of one group, a written test takes place
after the work and the obtained result is common to
the entire group, i.e. the average of the results of the
individual members. This method enhances the
interest of each student in making a fellow student
understand the part for which he/she is responsible.
The practical classes can be complemented with
seminaries that develop a subject related to the
objective of the subject.
Finally, the practical exercise is carried out by
groups of 2 to 4 persons and either chosen from a list
proposed by the professor or directly proposed by
the students. The proposed exercises have to be
related to one of the subjects of the subject and seek
BUILDING THE EUROPEAN HIGHER EDUCATION AREA - A Subject in Information Systems Security
399