Institutional review previewGraduate program information remains subject to final approval.
Course catalog

Cybersecurity Management · Proposed course

Cyber Risk Management & Governance

Course code
CSM 605
Credit hours
3
Program
MSCM
Delivery
Hybrid/Online

Course description

Course overview

This course focuses on the design, implementation, and management of enterprise-level cyber risk and governance frameworks. Students will learn to identify, quantify, and mitigate cybersecurity risks using industry standards and data-driven methods. The course explores NIST Risk Management Framework (RMF), ISO 31000, COSO, and FAIR models while emphasizing integration of cybersecurity governance into organizational strategy and compliance programs.

Course content is presented for institutional review and remains subject to approval and revision.

Academic focus

Course objectives

  1. 01

    Understand key principles and frameworks in cyber risk management and governance.

  2. 02

    Apply quantitative and qualitative methods to evaluate cybersecurity threats and vulnerabilities.

  3. 03

    Develop organizational governance structures that integrate cybersecurity oversight and accountability.

  4. 04

    Utilize data analytics tools to assess, monitor, and report on cyber risk exposure.

Learning outcomes

Upon completion

  1. CLO 1

    Apply governance and compliance frameworks such as NIST, ISO, and FAIR (maps to PLO 1, PLO 2).

  2. CLO 2

    Quantify cybersecurity risks using data analytics and modeling tools (maps to PLO 2, PLO 3).

  3. CLO 3

    Develop enterprise-level cybersecurity governance policies and procedures (maps to PLO 1, PLO 5).

  4. CLO 4

    Assess and report cyber risk posture to executive and regulatory stakeholders (maps to PLO 2, PLO 5, PLO 7).

Proposed syllabus

Weekly course schedule

The sequence below reflects the current 15-week syllabus and remains subject to institutional review.

  1. Week 1

    Introduction to Cyber Risk and Governance

  2. Week 2

    Risk Management Frameworks: NIST, ISO, COSO, and FAIR

  3. Week 3

    Cyber Risk Quantification and Modeling

  4. Week 4

    Threat Intelligence Integration into Risk Assessments

  5. Week 5

    Business Impact Analysis and Critical Asset Identification

  6. Week 6

    Regulatory and Compliance Drivers (SOX, HIPAA, GDPR)

  7. Week 7

    Governance, Risk, and Compliance (GRC) Platforms

  8. Week 8

    Midterm Exam and Governance Case Study

  9. Week 9

    Developing Risk Registers and Dashboards

  10. Week 10

    Incident Response Planning and Crisis Management

  11. Week 11

    Cyber Insurance and Third-Party Risk Management

  12. Week 12

    Metrics, Reporting, and Executive Risk Communication

  13. Week 13

    Integrating Governance with Strategic Leadership

  14. Week 14

    Final Project Presentations

  15. Week 15

    Final Exam and Course Wrap-Up

Evaluation

Assessment and grading

  • Risk Assessment Project – 30%
  • Midterm Exam – 20%
  • Final Exam – 20%
  • Case Study and Governance Report – 20%
  • Participation and Professional Engagement – 10%
A = 90–100%B = 80–89%C = 70–79%F = Below 70%

Course resources

Required texts and materials

  • Hubbard, D. W., & Seiersen, R. (2016). How to measure anything in cybersecurity risk. Wiley.
  • Fraser, J. R. S., Simkins, B. J., & Narvaez, K. (2021). Enterprise risk management: Today's leading research and best practices for tomorrow's executives (2nd ed.). Wiley.
  • Supplemental frameworks and readings (NIST RMF, ISO 31000, FAIR Model) provided via LMS.