Security Methods and Practice
CET4884 — Security Methods and Practice
← Course Modules
Course Description
Security Methods and Practice is an introduction to the fundamentals of how an enterprise's information, technology, facilities and people are protected, including business, legal, human resources and technology issues.
Within the SCNS taxonomy, CET is the Computer Engineering Technology prefix. Daytona State publishes this at 3 credits, offered fall, with GEB3213 (Business Communications) or ENC2210 (Technical Writing) as prerequisite, giving approximately 45 contact hours at the prefix's unsuffixed convention.
⚠ The prerequisite tells you what kind of course this is. It is a writing course, not a technical one — which signals that this is the management and governance course of the security sequence rather than a hands-on one. The four domains named in the description — information, technology, facilities and people — make the same point: enterprise security is not a technology problem, and the technical controls are one quarter of it.
That framing is genuinely useful. Most security failures in organisations are not cryptographic failures; they are people who were not trained, processes that were not followed, doors that were propped open, vendors who were not assessed, and risks that were accepted by someone who did not understand them.
Daytona State does not publish a lecture and laboratory split for its CET courses. The prefix's unsuffixed courses run consistently at 15 contact hours per credit — CET1588, CET2544, CET2691, CET2792, CET2793, CET2794, CET3505 and CET4542 are all published at 3 credits and 45 hours, without exception. Its C-suffixed courses run at 20 or above and its L-suffixed laboratories at 30. This course is unsuffixed and is priced at the unsuffixed convention.
Learning Outcomes
Required Outcomes
- Describe the scope of enterprise security across information, technology, facilities and people.
- Describe security governance and the role of executive accountability.
- Describe the confidentiality, integrity and availability model and its application.
- Describe risk management and the risk assessment process.
- Identify assets, threats, vulnerabilities and impacts.
- Assess and prioritise risk qualitatively and quantitatively.
- Describe risk treatment options: mitigate, transfer, avoid, and accept.
- Describe security policy, standards, procedures and guidelines and their relationship.
- Draft a security policy appropriate to an organisation.
- Describe security frameworks and control catalogues.
- Describe compliance obligations and their effect on security programmes.
- Describe legal and regulatory requirements affecting data protection.
- Describe breach notification obligations, including Florida's.
- Describe contractual and third-party risk management.
- Describe human resources security across the employment lifecycle.
- Describe personnel screening, separation of duties, and least privilege.
- Design and deliver security awareness training.
- Describe social engineering and its countermeasures.
- Describe physical and environmental security controls.
- Describe access control models and identity management.
- Describe business continuity and disaster recovery planning.
- Describe incident response from a management perspective.
- Describe security metrics and reporting to executives.
- Communicate security risk to a non-technical audience in writing and in speech.
Optional Outcomes
- Describe security economics and budgeting.
- Describe security architecture at an enterprise level.
- Describe audit processes and preparing for them.
- Describe insider threat programmes.
- Describe supply chain security.
- Prepare for a security management certification.
Major Topics
Required Topics
- Scope of enterprise security
- Security governance
- Confidentiality, integrity and availability
- Risk management process
- Asset, threat and vulnerability identification
- Risk assessment and prioritisation
- Risk treatment options
- Policies, standards and procedures
- Drafting security policy
- Security frameworks and control catalogues
- Compliance obligations
- Legal and regulatory requirements
- Breach notification obligations
- Third-party and contractual risk
- Human resources security
- Screening, separation of duties and least privilege
- Security awareness training
- Social engineering
- Physical and environmental security
- Access control and identity management
- Business continuity and disaster recovery
- Incident response management
- Security metrics and reporting
- Communicating risk to non-technical audiences
Optional Topics
- Security economics and budgeting
- Enterprise security architecture
- Audit preparation
- Insider threat programmes
- Supply chain security
- Security management certification
Resources & Tools
- The programme's laboratory and its isolated network — the only place you can lawfully practise most of this. Use every scheduled hour and every open-lab hour.
- Virtualisation software — VirtualBox is free, VMware Workstation Player is free for personal use; a home lab of virtual machines costs nothing but disk space.
- Kali Linux and the SANS SIFT Workstation — free tool distributions for security testing and forensics respectively.
- Autopsy and The Sleuth Kit (sleuthkit.org) — free and open-source forensic tools used professionally, not merely for teaching.
- NIST Computer Forensics Tool Testing programme (cftt.nist.gov) — free tool validation reports; the reference when you need to defend a tool choice.
- NIST Special Publications, especially SP 800-86 (forensic techniques in incident response) and SP 800-61 (incident handling) — free, authoritative, and directly examinable.
- CISA (cisa.gov) — free advisories, guidance, and free training resources.
- MITRE ATT&CK (attack.mitre.org) — free; the standard framework for describing adversary behaviour, and increasingly expected knowledge.
- TryHackMe, Hack The Box, and OverTheWire — lawful practice environments, with free tiers; the right place to practise offensive technique.
- CompTIA and Cisco Networking Academy materials — aligned to the certifications employers ask for.
- NIST Cybersecurity Framework and SP 800-53 — free; the control catalogue and framework most U.S. organisations reference.
- CIS Critical Security Controls — free; a prioritised, practical control set, and the best starting point for a small organisation.
- ISO/IEC 27001 and 27002 — the international standard for information security management (purchase required).
- Florida Department of Legal Affairs — free; the authority on Florida's breach notification requirements.
- (ISC)² and ISACA — professional bodies for the CISSP, SSCP, and CISA credentials, with student rates.
Career Pathways
- Information security analyst — SOC 15-1212; consistently among the fastest-growing occupations.
- Computer network support specialist — SOC 15-1231; computer user support specialist — SOC 15-1232.
- Network and computer systems administrator — SOC 15-1244.
- Digital forensics examiner — in law enforcement, in corporate investigations, and in consulting firms.
- Incident responder and security operations centre analyst — a large and growing entry route into security.
- Electrical and electronics engineering technologist or technician — SOC 17-3023, for the digital design pathway.
- Embedded systems and FPGA development — a specialised, well-paid pathway from the digital design sequence.
- Florida's defence, space, and simulation sector — the Space Coast, Orlando's simulation and training cluster, and Tampa's defence presence all hire heavily in these areas, and many roles require U.S. citizenship and a security clearance.
- Public sector and law enforcement — state and county agencies, and federal offices with a large Florida presence.
- Healthcare, financial services, and hospitality IT — all large Florida sectors with substantial compliance-driven security demand.
- Consulting and managed security service providers.
- ⚠ Many security and forensics roles require a clean background — criminal history, and for cleared work significant unresolved debt or foreign contacts, can be disqualifying. Find this out before investing in the pathway.
Special Information
⚠⚠ Communicating risk is the skill this course exists to build
- The prerequisite is a writing course, and that is not an accident. Security professionals fail in organisations far more often through poor communication than through poor technique.
- Executives decide on risk, cost, and consequence — not on vulnerabilities. "We have an unpatched CVE with a CVSS of 9.8" means nothing to a board; "an attacker could take our customer database offline for several days, and here is what that costs" is a decision they can make.
- Quantify where you honestly can, and be clear about uncertainty where you cannot. Invented precision destroys credibility permanently.
- Present options with trade-offs, not a single demand. Cost, residual risk, and effort for each.
- Accepting risk is a legitimate business decision — your job is to make sure it is made knowingly, by someone with authority, and recorded. Get risk acceptance in writing.
- Do not cry wolf. A practitioner who calls everything critical is ignored when something genuinely is.
- Write for the reader you have. The same finding needs one form for the system administrator and another for the chief financial officer.
- Say what you do not know. Overstating certainty is the fastest way to lose the standing you need.
⚠ People and processes fail more often than technology
- Most breaches involve a person doing something reasonable-seeming — clicking a convincing message, reusing a password, holding a door, sending a file to the wrong address.
- Awareness training that blames users does not work. Make the safe path the easy path, and make reporting a suspected mistake consequence-free — an employee who fears blame will hide an incident, and hidden incidents are the expensive ones.
- Social engineering defeats technical controls by design, and it works on capable people under time pressure, not only on careless ones.
- Off-boarding is routinely botched. Departing employees retaining access is one of the most common findings in any audit.
- Least privilege and separation of duties are cheap and effective, and they are resisted because they are inconvenient.
- Physical security is part of information security. A propped fire door, an unattended workstation, or a visitor left alone in an office defeats a great deal of technical control.
- Third parties are a first-order risk. Vendors with access to your systems or data extend your attack surface, and assessing them is a real obligation.
- A policy nobody reads or follows is worse than none, because it documents that you knew.
⚠⚠ Authorisation is the line between a security professional and a defendant
- Never access, scan, or test a system you do not have written permission to touch. Not a friend's network, not your employer's without authority, not a "harmless" port scan of a site you use. This is the one rule in this field that carries criminal consequences.
- Federal exposure: the Computer Fraud and Abuse Act criminalises unauthorised access to a protected computer, and "exceeding authorised access" has been read broadly.
- ⚠⚠ Florida exposure is separate and additional: the Florida Computer Crimes Act, Chapter 815, Florida Statutes, makes offences against intellectual property, computer users, and computer equipment punishable under state law independently of federal law. A student who assumes only federal law applies is wrong.
- Curiosity is not a defence, and neither is intent to help. Discovering a vulnerability and testing it without authorisation is an offence even when you meant to report it.
- Use the lab. Your programme provides an isolated environment precisely so you can practise techniques that would be unlawful elsewhere — build your own isolated lab at home too, and keep it off the production network.
- Get scope in writing before any authorised engagement — systems, addresses, times, techniques permitted, and who to contact when something breaks. A verbal "go ahead" protects nobody.
- Stay inside scope once you start. Following an interesting path onto a system not covered by the authorisation is where legitimate testers get into trouble.
- Responsible disclosure has a process. Follow the vendor's or organisation's published route, and do not publish details before it has been addressed.
- ⚠ Rule 11 applies. Computer crime, privacy, and disclosure law changes; verify current law and take advice rather than relying on a course guide.
⚠ Certifications carry real weight in this field — more than in most
- Information technology and security hire on demonstrated capability, and certifications are the common shorthand for it — frequently appearing as hard requirements in job postings and in government and contractor roles.
- Foundational: CompTIA A+ (hardware and operating systems), Network+, and Security+. Security+ in particular satisfies a widely cited U.S. Department of Defense baseline requirement, which makes it valuable in Florida's substantial defence and contractor sector.
- Networking: Cisco CCNA remains the recognised entry credential.
- Digital forensics: EnCE (EnCase), ACE (AccessData), CCE, and the SANS GCFE and GCFA. The SANS credentials are the most respected and by far the most expensive — employers frequently pay for them, so raise it at interview rather than self-funding.
- Security management: CISSP is the senior standard but requires several years of documented experience; SSCP is its practitioner-level counterpart and is reachable earlier.
- Time your certification to your coursework. Sit the examination while the material is fresh — pass rates fall sharply the longer graduates wait.
- Certifications expire. Most require continuing education and renewal, so plan for the ongoing cost.
- ⚠ A certification is not a substitute for the degree, and the degree is not a substitute for certifications. Employers in this field commonly want both, plus evidence you have actually built and broken things.
- Build a home lab and document it. Virtual machines cost nothing, and a candidate who can describe what they built and what went wrong interviews far better than one who lists courses.
How Florida course levels affect transfer
The first digit of an SCNS number denotes the year of offering, not transferability. Courses at the 1000 and 2000 levels transfer transparently between Florida public institutions, and 3000 to 4000 is unproblematic since both are upper division. The boundary that actually matters is 2000 to 3000, where lower-division credit generally cannot satisfy an upper-division requirement.
⚠ That boundary is live in this prefix. Daytona State offers CET courses at the 1000, 2000, 3000 and 4000 levels, the upper-division ones forming part of a bachelor of applied science. A 2000-level CET course does not substitute for its 3000- or 4000-level counterpart even where the subject matter overlaps — compare CET2880C/CET2881C (Data Forensics I and II, lower division) with CET4860/CET4861 (Introduction to and Advanced Digital Forensics, upper division). Confirm with an advisor which lower-division courses feed the BAS.
CET4884 is 3 credits and approximately 45 contact hours, offered fall at Daytona State, with GEB3213 or ENC2210 as prerequisite.
⚠ This is the management and governance course of the sequence, not a technical one — expect policy drafting, risk assessment, and written and spoken communication rather than laboratory work. It complements the technical courses CET4860, CET4861, and CET4862.