CMU5XX-INFOSEC

Information Security for Industry

A governance-focused module on securing critical infrastructure and corporate systems, covering information security policy, the NIST Cyber Security Framework, asset management, risk assessment, and the legal and compliance landscape.

When
2025/26, Semester 2
Institution
Birmingham Newman University
Credits
20 credits
Birmingham Newman University

Most organisations do not fail to secure their systems because they lack technical knowledge. They fail because security is treated as a technical problem rather than an organisational one. This module addresses the governance layer: the policies, frameworks, processes, and human structures that determine whether a technically capable organisation is actually secure.

The module was designed for students who understand the threat landscape and want to engage with how organisations actually manage it. It draws heavily on industry-standard guidance, particularly the NIST Cyber Security Framework, but always in the context of real decisions that real organisations face.

Why it matters

Critical infrastructure, financial systems, health data, and operational technology are all targets, and all depend on coherent information security governance to remain resilient. Regulation has followed: GDPR, NIS2, sector-specific compliance requirements, and board-level accountability for cyber risk are now standard expectations. The security professional who can navigate these requirements alongside the technical ones is significantly more valuable than one who cannot.

Cyber-physical security adds another dimension: as operational technology converges with IT systems, the consequences of security failures extend beyond data loss to physical disruption. Understanding how to model risk and design resilience across both domains is increasingly essential.

Module design

The module is structured to move students from concepts to application. Early weeks establish the foundations: what information security is, how systems are architected with security in mind, and what cyber-physical risks look like in practice. The middle of the module focuses on the tools of governance: policy formation, asset management, risk assessment, and the NIST Cyber Security Framework as an integrating structure. Later weeks address the human and organisational dimensions, enterprise roles, security culture, incident response, and compliance.

The aim throughout is that students can move fluently between the technical and managerial perspectives that security roles require. A security policy that no one understands and no one enforces is not a security control.

Topics

  • Introduction to secure information systems and architecture
  • Cyber-physical systems and critical infrastructure protection
  • Information security policies and procedures
  • Information systems planning and administration
  • Asset management and risk assessment
  • Organisational and human security, including insider threat
  • Cyber security management concepts and frameworks
  • The NIST Cyber Security Framework in practice
  • Enterprise roles, governance structures, and accountability
  • Developing and maintaining security plans
  • Incident response and business continuity planning
  • Compliance, law, and auditing

What students leave with

Students can engage confidently with information security at the governance level: analysing organisational risk, drafting and critiquing security policies, applying the NIST CSF to real scenarios, and understanding the legal and compliance landscape. These skills complement technical security knowledge and are in strong demand across both industry and the public sector, where the ability to operate at the interface of policy and practice is frequently what distinguishes effective security professionals.