Cybersecurity Management · Proposed course
Cyber Risk Management & Governance
- Course code
- CSM 605
- Credit hours
- 3
- Program
- MSCM
- Delivery
- Hybrid/Online
Course description
Course overview
This course focuses on the design, implementation, and management of enterprise-level cyber risk and governance frameworks. Students will learn to identify, quantify, and mitigate cybersecurity risks using industry standards and data-driven methods. The course explores NIST Risk Management Framework (RMF), ISO 31000, COSO, and FAIR models while emphasizing integration of cybersecurity governance into organizational strategy and compliance programs.
Course content is presented for institutional review and remains subject to approval and revision.
Academic focus
Course objectives
- 01
Understand key principles and frameworks in cyber risk management and governance.
- 02
Apply quantitative and qualitative methods to evaluate cybersecurity threats and vulnerabilities.
- 03
Develop organizational governance structures that integrate cybersecurity oversight and accountability.
- 04
Utilize data analytics tools to assess, monitor, and report on cyber risk exposure.
Learning outcomes
Upon completion
- CLO 1
Apply governance and compliance frameworks such as NIST, ISO, and FAIR (maps to PLO 1, PLO 2).
- CLO 2
Quantify cybersecurity risks using data analytics and modeling tools (maps to PLO 2, PLO 3).
- CLO 3
Develop enterprise-level cybersecurity governance policies and procedures (maps to PLO 1, PLO 5).
- CLO 4
Assess and report cyber risk posture to executive and regulatory stakeholders (maps to PLO 2, PLO 5, PLO 7).
Proposed syllabus
Weekly course schedule
The sequence below reflects the current 15-week syllabus and remains subject to institutional review.
- Week 1
Introduction to Cyber Risk and Governance
- Week 2
Risk Management Frameworks: NIST, ISO, COSO, and FAIR
- Week 3
Cyber Risk Quantification and Modeling
- Week 4
Threat Intelligence Integration into Risk Assessments
- Week 5
Business Impact Analysis and Critical Asset Identification
- Week 6
Regulatory and Compliance Drivers (SOX, HIPAA, GDPR)
- Week 7
Governance, Risk, and Compliance (GRC) Platforms
- Week 8
Midterm Exam and Governance Case Study
- Week 9
Developing Risk Registers and Dashboards
- Week 10
Incident Response Planning and Crisis Management
- Week 11
Cyber Insurance and Third-Party Risk Management
- Week 12
Metrics, Reporting, and Executive Risk Communication
- Week 13
Integrating Governance with Strategic Leadership
- Week 14
Final Project Presentations
- Week 15
Final Exam and Course Wrap-Up
Evaluation
Assessment and grading
- Risk Assessment Project – 30%
- Midterm Exam – 20%
- Final Exam – 20%
- Case Study and Governance Report – 20%
- Participation and Professional Engagement – 10%
Course resources
Required texts and materials
- Hubbard, D. W., & Seiersen, R. (2016). How to measure anything in cybersecurity risk. Wiley.
- Fraser, J. R. S., Simkins, B. J., & Narvaez, K. (2021). Enterprise risk management: Today's leading research and best practices for tomorrow's executives (2nd ed.). Wiley.
- Supplemental frameworks and readings (NIST RMF, ISO 31000, FAIR Model) provided via LMS.
