B3110 - System Security and Privacy Workshop Classes - Cesena Campus

Academic Year 2026/2027

  • Moduli: Marco Canducci (Modulo 1) Giovanni Lanotte (Modulo 2)
  • Teaching Mode: In-person learning (entirely or partially) (Modulo 1); In-person learning (entirely or partially) (Modulo 2)
  • Campus: Cesena
  • Corso: First cycle degree programme (L) in Computer Systems Technologies (cod. 6007)

    Also valid for First cycle degree programme (L) in Computer Systems Technologies (cod. 6007)

Learning outcomes

Upon completion of the course, the student knows the basic principles of cybersecurity and the main security issues of computer systems and networks. They know the communication protocols and mechanisms used to ensure the secure transfer of information. They are able to critically evaluate the security of a computer system, identifying potential vulnerabilities and implementing all necessary countermeasures to mitigate the identified issues and increase the robustness of the system. They know the principles and methodologies underlying directory services and are able to manage a small-scale system based on proprietary or open-source directory services. They know the methods for integrating an application with a directory service deployed in the cloud using the services of major cloud providers. They are able to contribute to the design of systems, including cloud-based ones, where security is an essential and structural element. They are able to design the mechanisms for securing devices on the Internet and distributed systems in the cloud, utilizing the frameworks available on these cloud platforms. They are able to use penetration testing tools to validate the security of a system by searching for its vulnerabilities and measuring the effects of exploiting these vulnerabilities.

Course contents

  • Introduction and principles of cybersecurity
  • Reference standards and regulations for secure information management
  • Fundamentals of cryptography and data protection
  • Application security and OWASP Top 10
  • Secure Software Development Lifecycle
  • Red teaming and Penetration testing

Readings/Bibliography

All the mandatory content is available on the slides presented in class. Any further reading (optional) will in any case be provided directly on the slides via links or references.

Teaching methods

In-person classroom lectures (Cesena or Imola), available simultaneously via a Teams meeting, recorded and made available for later viewing directly on the course channel.

Assessment methods

  • Written exam, in person, to assess theoretical knowledge (accounts for 35% of the final grade)
  • Oral exam, in groups, in person or remotely, to assess practical skills through the presentation of a project chosen from the topics proposed by the professor (accounts for 65% of the final grade)

Teaching tools

  • Slides provided by the professor during the course
  • References to industry standards and frameworks (e.g., OWASP, NIST, ...)
  • In-depth study and experimentation encouraged, also through the use of Artificial Intelligence tools

Office hours

See the website of Marco Canducci

See the website of Giovanni Lanotte