- Docente: Andrea Melis
- Credits: 6
- SSD: IINF-05/A
- Language: English
- Moduli: Andrea Melis (Modulo 1)
- Teaching Mode: In-person learning (entirely or partially) (Modulo 1)
- Campus: Cesena
-
Corso:
Second cycle degree programme (LM) in
Computer Science and Engineering (cod. 6699)
Also valid for Second cycle degree programme (LM) in Digital Transformation Management (cod. 6823)
Learning outcomes
At the end of the course, the student knows the basic principles of computer security and he/she is able to identify the main problems of computer and network security. He/she gets to understand and explain the main protocols and mechanisms used for securing communications and data transfer. He/she is able to perform a critical evaluation of the security of a computing infrastructure and to suggest the best countermeasures to mitigate the vulnerabilities, reduce the risk and increase the resilience to attacks. He/she is also capable of contributing to the design of systems that are secure by design and understanding the basic problems of computer forensics. Finally, he/she is able to design and contribute to the enhancement of the security of devices exposed to the Internet.
Course contents
The course aims to provide students with the knowledge required to understand cybersecurity as a strategic governance discipline, going beyond the purely technical aspects of information security. It covers the main cyber risk management models, international frameworks, the European and national regulatory landscape, and the methodologies used to design, implement, and evaluate cybersecurity programs within both public and private organizations.
Upon successful completion of the course, students will be able to assess the cyber risk profile of an organization, understand the organizational, economic, and regulatory implications of cyber incidents, apply established security management frameworks, and contribute to the definition of cybersecurity strategies, policies, and processes aligned with both business objectives and regulatory requirements.
The course approaches cybersecurity from a managerial, organizational, and strategic perspective, examining the role of information security in the governance of modern organizations.
Following an introduction to the current cyber threat landscape and the evolution of the digital ecosystem, the course presents the fundamental concepts of cyber risk management, cyber resilience, and security governance.
The course then explores the most widely adopted international cybersecurity frameworks and standards, including the NIST Cybersecurity Framework, the ISO/IEC 27000 family of standards, the NIST Risk Management Framework, the CIS Controls, and other reference models commonly used in cybersecurity management.
Particular attention is devoted to the European and national regulatory landscape, with an in-depth discussion of major directives and regulations such as NIS2, the Cyber Resilience Act (CRA), the Cyber Solidarity Act, the General Data Protection Regulation (GDPR), DORA, the AI Act, and the Italian National Cybersecurity Strategy.
Readings/Bibliography
Course materials include lecture slides, scientific papers, white papers, technical documentation, international standards, guidelines published by ENISA, NIST, CISA, and the Italian National Cybersecurity Agency (ACN), together with documentation issued by the European Commission and additional material made available through the University's Virtual Learning Environment.
Throughout the course, students may also discuss technical reports and publications produced by governmental institutions, industry, and research organizations, ensuring that course contents remain aligned with the latest developments in the cybersecurity landscape.
Teaching methods
Teaching activities include lectures complemented by guided discussions, case study analysis, reviews of real-world cyber incidents, collaborative exercises, and student presentations.
Assessment methods
The final assessment takes into account both students' participation in the course activities and their overall achievement of the intended learning outcomes.
Teaching tools
All teaching materials, including lecture slides, scientific articles, supplementary readings, regulatory references, datasets, and case studies, will be progressively published on the University's Virtual Learning Environment after each lecture.
Additional resources may be provided throughout the course to reflect the continuous evolution of cybersecurity technologies, regulations, and emerging threats.
Office hours
See the website of Andrea Melis