Principles of Information Assurance introduces the foundations of information security: the threats and vulnerabilities present in the current cyber landscape, the principles that govern how systems and data are protected, and the organizational and technical controls used to protect them. It is the survey course of a cybersecurity program — the one that establishes vocabulary, mental models, and the security mindset that later courses build on.
Within the SCNS taxonomy, CIS is the Computer Information Sciences prefix. This course sits in the second year of an A.S. in cybersecurity or network engineering, after an introductory networking course, and is the prerequisite for the more specialized security courses — at Daytona State it is required before CNT2404 Intrusion Detection and Response. It appears at approximately four Florida institutions. The C suffix in the statewide inventory denotes an integrated lecture-and-laboratory course.
The organizing idea worth stating early: security is not a product or a checklist. It is the practice of managing risk under constraint — of deciding what is worth protecting, from whom, at what cost, and accepting that no system is ever fully secure. Students who internalize that reason well about problems they have never seen. Students who memorize control lists do not.
Florida course inventories carry this number under the title "Cybersecurity Analysis", and with a C suffix. Daytona State publishes it as CIS2350 "Principles of Information Assurance" — no suffix, and a broader, more foundational scope than "analysis" implies. The distinction matters: an analysis course suggests hands-on detection and investigation work, which at Daytona State is a separate, later course (CNT2404). Read the catalog description rather than the inventory title, and note that the credit and contact-hour values differ between the suffixed and unsuffixed forms.
This is the most important thing in the course, and it is worth being blunt about. The techniques discussed here are the same techniques attackers use, and the difference between a security professional and a defendant is authorization — nothing else.
Under the Florida Computer Crimes Act, Chapter 815, Florida Statutes, unauthorized access to a computer, system, or network is a criminal offense, with offense levels rising to felony depending on intent and harm. The federal Computer Fraud and Abuse Act (18 U.S.C. § 1030) applies in parallel. Neither statute contains an exception for curiosity, for good intentions, or for students.
The rules that keep a career intact: run tools only against systems you own or in the course lab; never scan the campus network, an employer's network, or a friend's server without written permission; and understand that a scan is itself an access attempt. Students are periodically expelled and occasionally prosecuted for this, almost always without malicious intent. If you find a real vulnerability in a real system, do not probe it further — report it through the organization's disclosure channel, and document what you did.
Students enter this field on the strength of headlines about millions of unfilled security jobs. That figure is real in aggregate and badly misleading about entry level, and it is worth saying plainly so students plan rather than get discouraged.
The great majority of open security positions are mid-level and senior — they require three to five years of prior IT experience because security is applied on top of systems and networks you must already understand. Very few organizations hire someone with no IT background directly into a security role, and the number of applicants for the genuinely entry-level positions that exist is very large.
The realistic and reliable path: get an IT job first — help desk, desktop support, network operations, systems administration — and move into security from inside the organization within one to three years. That route is faster in practice than applying to security roles from outside. Two things accelerate it materially: a certification (Security+ is the common baseline and is DoD 8570/8140 approved, which matters a great deal in Florida's defense corridor), and demonstrable hands-on work — a home lab, capture-the-flag participation, a documented project. The degree opens the door; the lab and the certificate get the interview.
Florida-specific and genuinely advantageous: the concentration of defense and government contractors around the Space Coast, Tampa, and Panama City means security clearance eligibility is itself a hiring advantage. A clearance cannot be self-obtained — it requires a sponsoring employer — but candidates who are eligible (U.S. citizenship, a clean financial and criminal record) should say so, and should protect that eligibility deliberately, because financial problems are the most common reason clearances are denied.
Beyond the criminal statutes, students should know the compliance environment they will work inside:
Breach notification law and CMMC requirements have both been amended repeatedly — rule 11 applies; verify current requirements rather than relying on a textbook.
Security is one of the fields where generative and machine learning tools have changed practice substantively rather than cosmetically, and a current course should address it directly.
Where AI genuinely helps. Log summarization and triage, explaining unfamiliar code or a suspicious script, drafting detection logic and queries, generating policy and documentation first drafts, and accelerating research into an unfamiliar technology. Machine learning underlies user and entity behavior analytics and much modern endpoint detection, and understanding roughly how those models make decisions is now part of the job.
Where it fails, and where the risk is. Models produce confident, plausible, and sometimes wrong output — including invented CVE numbers, invented tool flags, and configuration advice that is subtly insecure. Never paste production logs, configurations, credentials, or customer data into a public AI service; that is a data disclosure, and in a regulated environment it can itself be a reportable event. On the offensive side, AI has measurably improved attacker capability — phishing that no longer has the tell-tale language errors students are taught to look for, and convincing voice and video deepfakes used for business email compromise and help-desk social engineering. The old advice to spot phishing by its bad grammar is now obsolete, and students should be taught verification of the request through a separate channel instead.
Professional responsibility. A security professional owns the output they act on, whatever produced it. Verify AI-generated configuration, code, and advice against primary documentation before applying it, and follow your institution's academic integrity policy on AI use — which varies by course and by instructor.
The 3 credits and 60 contact hours reported here reflect the C-suffixed integrated form carried in the statewide inventory, at the 20-hours-per-credit convention this repository's CET and CNT integrated courses use consistently. Daytona State's unsuffixed CIS2350 is 3 credits with prerequisite CET1600, offered fall and spring; a lecture-only form would run closer to 45 hours. Confirm on your institution's syllabus.
Expect a mix of concept examinations and hands-on laboratory work in a virtualized environment. Where the course is aligned to CompTIA Security+, taking the certification examination immediately after the course — while the material is fresh — is materially easier than deferring it.
How Florida course levels affect transfer: the first digit of an SCNS number denotes the year of offering, not transferability. 1000- and 2000-level courses transfer transparently between Florida public institutions; the boundary that matters is 2000 to 3000, where lower-division credit generally cannot satisfy an upper-division requirement. CIS2350C is 2000-level lower-division credit, and it will not substitute for an upper-division security course such as CIS4360 in a bachelor's program — a substitution students frequently assume and advisors frequently have to correct. Note also the suffix caution above: CIS2350 and CIS2350C are different numbers and carry different contact hours.
Generated September 2, 2026 · Updated September 2, 2026