course-details-portlet

TM8104

ICT-Security Evaluation

Choose study year

Lessons are not given in the academic year 2013/2014

Credits 7.5
Level Doctoral degree level
Language of instruction English

About

About the course

Course content

The course is about principles and methods for development of criteria for ICT security evaluation and how these are used to evaluate security.

Example topics are: protection profiles (PPs),security targets (STs), security functionality, functionality classes, assurance correctness, assurance effectiveness, evaluation assurance levels (EALs), certification, accreditation, standardisation of evaluation criteria, national scheme for evaluation and certification.

Learning outcome

A. Knowledge: After having completed the course, the students shall have obtained basic knowledge of the principles and methods which are employed for evaluation of the security of an ICT product or service
B. Skills: To be able to perform a security evaluation based on the requirements expressed in the international standard ISO/IEC IS 15408 Evaluation Criteria for IT Security, Parts 1/3 and the methods described in CEM

Learning methods and activities

Lectures, colloquia, discretionary exercises. If postponed exam (continuation exam) is used, an oral exam may be used as opposed to the normal written exam.

The grading rule is pass/fail. The minimum passing grade is 70/100 points (70%).

Course materials

Internationally standardised criteria for ICT Security evaluation (ISO 15408, Part 1-3, ISO 27001), security evaluation methodology (CEM).

Credit reductions

Course code Reduction From
DIE5939 7.5 sp
This course has academic overlap with the course in the table above. If you take overlapping courses, you will receive a credit reduction in the course where you have the lowest grade. If the grades are the same, the reduction will be applied to the course completed most recently.

Subject areas

  • Communication and Information Science
  • Sikkerhetsteknikk
  • Telecommunication
  • Telematics

Contact information

Department with academic responsibility

Department of Information Security and Communication Technology