COM227 Cybersecurity in Action and Professional Issues
| Summary |
This module has two components. The first component aims to teach students about the key security properties needed in today's computer systems, how these properties can be attacked, and the ways to prevent such attacks. Properties covered include: confidentiality, integrity, availability, anonymity, and privacy. We will also cover threat modelling approaches and countermeasure determination. Countermeasures addressed include authentication, access control, basic cryptography, and web and network security, and some hardware aspects of security. We will also outline some elements of the security of advanced systems, e.g. message inference attacks in online ML systems and the role of quantum technologies in cybersecurity. The second component looks more widely at the professional issues in the computing discipline, particularly the commercial context and relevant legal matters. Issues such as liability, IPR and privacy regulation are investigated. The goal is to develop not only technically proficient but also ethically responsible professionals, who are aware of the consequences of their actions on individuals, organisations, and society at large, thereby preparing them to be conscientious and ethical leaders in the cybersecurity field. |
| Session |
Spring 2026/27 |
| Credits |
20 |
| Assessment |
Formal Examinations
|
| Lecturer(s) |
Dr Mahshid Delavar, Prof. Emma Norling, Dr Mark Stevenson, & Dr Prosanta Gope |
| Resources |
|
| Aims |
This unit aims to:
- Enable students to identify and analyse the risks posed by potential security threats to computer system.
- Enable students to identify and implement countermeasures to control such risks.
- Develop ethically responsible professionals, who are aware of the consequences of their actions on individuals, organisation, and society at large.
- Introduce students to key areas of financial and legal risk that engineers should be aware of in their working environment.
|
| Learning Outcomes |
By the end of the module the student will be able to:
- Clearly describe and explain the security properties that secure systems or components are expected to uphold in various contexts.
- Identify and describe potential threats to security properties, explain how such threats might be realized, assess the likelihood of such occurrences, and propose appropriate countermeasures.
- Demonstrate familiarity with key professional, ethical, legal, and social issues in cybersecurity (including processes for handling forensic evidence).
- Identify the risk of legal liability arising from private law and the legal protections available in relation to the ownership and transferability of intellectual property rights.
- Demonstrate an understanding of the commercial context of management principles in the computing industry.
|
| Content |
For the security component of this module, it will draw upon topics covered in first and second year teaching, looking at them from a security perspective. In addition, other common aspects of security systems will be highlighted with practical examples.
For the professional issues component, it will consider financial and legal issues that impact on practitioners in the computing industry.
|
| Teaching Method |
For the cybersecurity component: Lectures and lab classes. For the professional issues component: Lectures and tutorials. |
| Feedback |
Available during tutorials and laboratory classes. |
|