<?xml version="1.0" encoding="UTF-8"?>
<CourseUnit xmlns="http://www.manchester.ac.uk/CUICourseUnitDetails" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.manchester.ac.uk/CUICourseUnitDetails.xsd">
  <UnitCode Applicant="Y" Label="Unit code" Student="Y">
    <Code>BMAN32301</Code>
  </UnitCode>
  <UnitTitle Applicant="Y" Label="Unit title" Student="Y">
    <Title>IT Risk, Cybersecurity and Governance</Title>
  </UnitTitle>
  <MaxUnits Applicant="Y" Label="Credit rating" Student="Y">
    <Units>10</Units>
  </MaxUnits>
  <TeachingPeriods Applicant="Y" Label="Teaching period(s)" Student="Y">
    <Period>Semester 1</Period>
  </TeachingPeriods>
  <AcademicCareer Applicant="Y" Label="Academic career" Student="Y">
    <Value>Undergraduate</Value>
  </AcademicCareer>
  <UnitLevel Applicant="Y" Label="Unit level" Student="Y">
    <Level>Level 3</Level>
  </UnitLevel>
  <StaffList Applicant="Y" Label="Teaching staff" RoleLabel="Course Unit Role" Student="Y">
    <StaffMember>
      <Name>Erik Beulen</Name>
      <Role>Unit coordinator</Role>
    </StaffMember>
  </StaffList>
  <OfferedBy Applicant="Y" Label="Offered by" Student="Y">
    <OrganisationList>
      <Organisation>
        <OrgName></OrgName>
      </Organisation>
    </OrganisationList>
    <GroupList>
      <Group>
        <GroupName></GroupName>
      </Group>
    </GroupList>
    <FheqLevels>
      <FheqLevel>
        <LevelNumber>1</LevelNumber>
        <LevelName>FHEQ level (Framework for Higher Education Qualifications) ' Undefined ' </LevelName>
      </FheqLevel>
    </FheqLevels>
    <Ects>
      <MaxUnits>European Credit Transfer &amp; Accumulation System Rating :   5.0</MaxUnits>
    </Ects>
  </OfferedBy>
  <MarketingOverview Applicant="Y" Label="Marketing Course unit overview" Student="">
    <Content>&lt;p&gt;The increasing drive to Digital Transformation has brought about new types of risk related to the prevalence of digital at every level of organisations. The resultant security breaches have created a new awareness of risk among the public, businesses and lawmakers, as well as awareness of the need for cybersecurity risk management frameworks and education. This course unit delivers understanding of the concepts of risk, cybersecurity and governance and initial skills in applying these concepts for managing cybersecurity risks in organisational context. &amp;nbsp;&lt;/p&gt;</Content>
  </MarketingOverview>
  <UnitOverview Applicant="" Label="Course unit overview" Student="Y">
    <Content>&lt;p&gt;The increasing drive to Digital Transformation has brought about new types of risk related to the prevalence of digital at every level of organisations. The resultant security breaches have created a new awareness of risk among the public, businesses and lawmakers, as well as awareness of the need for cybersecurity risk management frameworks and education. This course unit delivers understanding of the concepts of risk, cybersecurity and governance and initial skills in applying these concepts for managing cybersecurity risks in organisational context. &amp;nbsp;&lt;/p&gt;</Content>
  </UnitOverview>
  <Aims Applicant="Y" Label="Aims" Student="Y">
    <Content>&lt;p&gt;The course unit aims to: &amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Enable students to understand the implication of implementing efficient strategies for undertaking and managing IT risk, cybersecurity and IT governance. &amp;nbsp;&lt;/li&gt;&lt;li&gt;Enable students to practice initial skills of managing risk strategies and applying models to support IT governance.&lt;/li&gt;&lt;/ul&gt;</Content>
  </Aims>
  <LearningOutcomes Applicant="Y" Label="Learning outcomes" Student="Y">
    <Content>&lt;p&gt;Learning outcomes:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;To understand the concepts and principles of IT risk, cybersecurity and governance. &amp;nbsp;&lt;/li&gt;&lt;li&gt;To apply, critically, IT risk tools and techniques to analyse and evaluate disruptive events.&lt;/li&gt;&lt;li&gt;To develop and justify recommendations based on appropriate research. &amp;nbsp;&lt;/li&gt;&lt;li&gt;To work collectively to ensure the delivery of a business-focused risk management strategy.&lt;/li&gt;&lt;li&gt;To communicate findings in writing. &amp;nbsp;&lt;/li&gt;&lt;/ul&gt;</Content>
  </LearningOutcomes>
  <Knowledge Applicant="Y" Label="Knowledge and understanding" Student="Y">
    <Content></Content>
  </Knowledge>
  <IntellectualSkills Applicant="Y" Label="Intellectual skills" Student="Y">
    <Content></Content>
  </IntellectualSkills>
  <PracticalSkills Applicant="Y" Label="Practical skills" Student="Y">
    <Content></Content>
  </PracticalSkills>
  <TransferableSkills Applicant="Y" Label="Transferable skills and personal qualities" Student="Y">
    <Content></Content>
  </TransferableSkills>
  <EmployabilitySkillsList Applicant="Y" Label="Employability skills" Student="Y">
    <Skill>
      <SkillId>Other</SkillId>
      <SkillDescription>Risk management and especially managing risks related to cybersecurity is a growing industry with increasing opportunities for graduates who have the skills and abilities to make important business decisions. Fuelled by the greater need to soundly manage complex and continually  evolving  IT  systems,  organisations  are seeking better ways to effectively manage IT related activities and understand their impact.</SkillDescription>
    </Skill>
  </EmployabilitySkillsList>
  <Syllabus Applicant="Y" Label="Syllabus" Student="Y">
    <Content>&lt;p&gt;Syllabus:&lt;/p&gt;&lt;p&gt;1. Digital transformation and associated security issues with new technologies &amp;nbsp;&lt;/p&gt;&lt;p&gt;2. Managing the risks of Digital Transformation &amp;nbsp;&lt;/p&gt;&lt;p&gt;3. Risk management process, architecture and structure. &amp;nbsp;&lt;/p&gt;&lt;p&gt;4. Risk assessment tools and techniques. &amp;nbsp;&lt;/p&gt;&lt;p&gt;5. Principles of IT governance and cybersecurity management &amp;nbsp;&lt;/p&gt;&lt;p&gt;6. IT Risks: cybersecurity principles and standards &amp;nbsp;&lt;/p&gt;&lt;p&gt;7. Cybersecurity risk management framework: actors, events and vulnerabilities &amp;nbsp;&lt;/p&gt;&lt;p&gt;8. Security by Design &amp;nbsp;&lt;/p&gt;</Content>
  </Syllabus>
  <TeachingMethods Applicant="Y" Label="Teaching and learning methods" Student="Y">
    <Content></Content>
  </TeachingMethods>
  <AssessmentMethods Applicant="Y" Label="Assessment methods" Student="Y">
    <IntroText> </IntroText>
    <Method>
      <MethodId>2</MethodId>
      <MethodName>Written assignment (inc essay)</MethodName>
      <MethodWeight>40%</MethodWeight>
    </Method>
    <Method>
      <MethodId>3</MethodId>
      <MethodName>Report</MethodName>
      <MethodWeight>60%</MethodWeight>
    </Method>
  </AssessmentMethods>
  <FeedbackMethods Applicant="Y" Label="Feedback methods" Student="Y">
    <Content>&lt;ul&gt;&lt;li&gt;Informal advice and discussion during the lectures. &amp;nbsp;&lt;/li&gt;&lt;li&gt;Responses to student emails and questions from course coordinator including feedback provided to a group via an online discussion forum. &amp;nbsp;&lt;/li&gt;&lt;li&gt;Written and/or verbal comments on assessed/non-assessed coursework. &amp;nbsp;&lt;/li&gt;&lt;li&gt;Generic feedback posted on Blackboard regarding overall performance. &amp;nbsp;&lt;/li&gt;&lt;/ul&gt;</Content>
  </FeedbackMethods>
  <RequirementsList Applicant="Y" Label="Pre/co-requisites" Student="Y">
    <Requirement>
      <UnitCode>BMAN32141</UnitCode>
      <UnitTitle>Business IT Architecture</UnitTitle>
      <RequirementType>Co-Requisite</RequirementType>
      <Description>Compulsory</Description>
    </Requirement>
    <Requirement>
      <UnitCode>BMAN24630</UnitCode>
      <UnitTitle>Business Analysis</UnitTitle>
      <RequirementType>Pre-Requisite</RequirementType>
      <Description>Compulsory</Description>
    </Requirement>
    <AdditionalRequirement></AdditionalRequirement>
  </RequirementsList>
  <AcademicPrograms Applicant="Y" Label="Academic programmes" Student="Y">
    <AcademicProgram>
      <Program></Program>
      <Plan></Plan>
      <Level></Level>
      <Requirement></Requirement>
    </AcademicProgram>
  </AcademicPrograms>
  <FreeChoice Applicant="Y" Label="Available as a free choice unit?" Student="Y">
    <Content>N</Content>
  </FreeChoice>
  <Accreditation Applicant="Y" Label="Accreditation" Student="Y">
    <Content></Content>
  </Accreditation>
  <RecommendedReading Applicant="Y" Label="Recommended reading" Student="Y">
    <Content>&lt;p&gt;Recommended reading &amp;nbsp;&lt;/p&gt;&lt;p&gt;Fundamentals of Risk Management 5th Edition by Paul Hopkin, Kogan Page, 2018.&lt;/p&gt;&lt;p&gt;Information Security Principles 3rd Edition by Andy Taylor et al. BCS, 2020. &amp;nbsp;&lt;/p&gt;&lt;p&gt;Cyber Risk Management: Prioritize Threats, Identify Vulnerabilities and Apply Controls Kindle Edition by Christopher J Hodson, Kogan Page; 1st edition (3 Jun. 2019)&lt;/p&gt;</Content>
  </RecommendedReading>
  <StudyHours Applicant="Y" Label="Study hours" Student="Y">
    <IntroText> </IntroText>
    <ScheduledHours Applicant="Y" Label="Scheduled activity hours" Student="Y">
      <ActivityHours>
        <ActivityType>Lectures</ActivityType>
        <Hours>20</Hours>
      </ActivityHours>
      <ActivityHours>
        <ActivityType>Practical classes &amp; workshops</ActivityType>
        <Hours>5</Hours>
      </ActivityHours>
    </ScheduledHours>
    <PlacementHours Applicant="Y" Label="Placement hours" Student="Y">
      <ActivityHours>
        <ActivityType></ActivityType>
        <Hours>0</Hours>
      </ActivityHours>
    </PlacementHours>
    <TotalHours Applicant="Y" Label="Independent study hours" Student="Y">
      <Hours>75</Hours>
    </TotalHours>
  </StudyHours>
  <Notes Applicant="Y" Label="Additional notes" Student="Y">
    <Content>&lt;p&gt;Additional notes &amp;nbsp;&lt;/p&gt;&lt;p&gt;Pre-requisites: &amp;nbsp;Business Analysis (BMAN24630)&lt;/p&gt;&lt;p&gt;Co-requisites: Business IT Architecture (BMAN32141)&lt;/p&gt;&lt;p&gt;Programme Restrictions: Core for ITMB and ITMB with IE&lt;/p&gt;&lt;p&gt;Peer Assessment: To ensure that all group members will make a significant contribution to the assignment, marks within student groups can differ based on the results of a peer assessment between group members ( peer assessment form is attached).&lt;/p&gt;&lt;p&gt;For Academic Year : 2024/25&lt;/p&gt;&lt;p&gt;Updated: &amp;nbsp;April 2024&lt;/p&gt;&lt;p&gt;Approved by: &amp;nbsp;Undergraduate Committee&lt;/p&gt;</Content>
  </Notes>
</CourseUnit>
