24,428 courses · 2,504 curriculum guides Sponsored by eAgentic Software Sponsored by eAgentic Software

CIS4361: Applied Security

CIS4361 — Applied Security
← Course Modules
3 credit hours 45 contact hours Prerequisites: One programming course at UWF -- COP2253 (Java), COP2334 (C++) or COP2830 (Script Programming). That modest gate is deliberate: this is the broad foundations course, accessible early in a computing degree. Practice varies statewide, with some institutions requiring networking or operating systems first. Take this before the deeper specializations -- it supplies the vocabulary and mental model that CNT4403 and the forensics/ethical-hacking courses assume. v1.0

Course Description

CIS4361 Applied Security is the survey course that establishes what information security actually is before a student specialises in any part of it. It is the course where the field's organising vocabulary — confidentiality, integrity, availability, threat, vulnerability, risk, control — stops being a list of words and becomes a framework for reasoning about systems.

The course is offered at approximately seven Florida institutions, including the University of West Florida, Florida State University, the University of Central Florida, the University of South Florida, Florida A&M University, Pasco-Hernando State College and Seminole State College.

At the University of West Florida the course is titled Information Technology Security and is offered by the Department of Cybersecurity and Information Technology in the College of Science and Engineering. UWF's description sets the scope precisely: an overview of security challenges and countermeasure strategies in the information systems environment, covering definitions, concepts, elements and goals, incorporating industry standards and practices, with a focus on the confidentiality, availability and integrity aspects of information systems. The prerequisite is one programming course — COP 2253 (Java), COP 2334 (C++) or COP 2830 (Script Programming).

That prerequisite tells you what kind of course this is. One programming course, any language, is a modest gate. This is a broad foundations course accessible relatively early in a computing degree, not a deep technical course requiring systems and networking background. Its sibling course at UWF, CNT 4403 (Computer and Network Security), sits several courses further along and requires data structures plus a systems or networking course — a genuinely different level. Students should not confuse the two, and should generally take this one first.

The statewide title is "Applied Security," and the word "applied" is worth interpreting carefully. It does not mean the course is primarily hands-on hacking. It means the course treats security as something practised on real systems under real constraints rather than as abstract cryptographic theory — policies that people have to follow, controls that cost money, risks that must be prioritised because they cannot all be eliminated. That framing is why the course spends real time on standards, governance and risk management alongside the technical material, and it is a large part of what makes it professionally useful.

The intellectual shift the course demands is the one every security professional makes: from asking "how does this work?" to asking "how does this fail, and who benefits when it does?" Ordinary computing education teaches systems as they are intended to operate. Security requires reasoning about an adversary who is actively looking for the gap between intended operation and actual operation. Students who make that shift find everything afterwards easier; students who do not tend to memorise attack names without understanding why they work.

Learning Outcomes

Required Outcomes

Optional Outcomes

Major Topics

Required Topics

Optional Topics

Resources & Tools

Career Pathways

Information security has genuine, sustained demand and a well-documented workforce shortage, and Florida is a substantial market. This course is the foundations course for essentially every route into the field.

Florida's security employment base is larger than students expect and is concentrated in identifiable places. The state hosts substantial defence and intelligence-adjacent employment around Tampa — home to U.S. Central Command and U.S. Special Operations Command at MacDill Air Force Base, which anchors a large cleared-contractor community — and around the Space Coast, Orlando (simulation and training industry), Pensacola (with a significant Navy cyber and cryptologic presence), and the defence contractors operating statewide including Lockheed Martin, Northrop Grumman, L3Harris and Leidos. Financial services security roles concentrate in Jacksonville, Tampa and South Florida; healthcare security roles across the state's large hospital systems; and the cruise, logistics and hospitality industries all carry significant security operations. State and local government, Florida's universities, and the utilities add further demand.

A note on UWF specifically: the University of West Florida hosts a nationally designated centre for cybersecurity education and has served as a regional hub for cybersecurity workforce development programmes. Students at UWF should investigate what that infrastructure makes available to them — scholarships, competitions, training programmes and employer connections — because it is a genuine advantage and is under-used by undergraduates.

Special Information

⚠ Course title variation across Florida

The statewide title is Applied Security; the University of West Florida titles CIS 4361 Information Technology Security. Other institutions use variants including Information Security and Computer Security. This is title drift rather than a subject difference — the descriptions converge on the same foundations material — but it means a student searching a catalogue for "Applied Security" may not find the course that satisfies the requirement. Search by number.

Related numbers to distinguish, because students confuse them and the distinction affects sequencing:

Prerequisites and where the course sits

UWF requires one programming course — COP 2253, COP 2334 or COP 2830 — which is a deliberately accessible gate. Practice varies across the state: some institutions require a networking course, some require operating systems, and some position the course later in the major. The modest prerequisite makes this a good early upper-division course, and taking it before the deeper specialisations is the right sequence: it supplies the vocabulary and the mental model that the specialised courses assume.

Students in adjacent majors — information technology, computer science, management information systems, and increasingly business and criminal justice — take this course as an elective, and it works well for that purpose because it is not narrowly technical.

Articulation and transfer

CIS4361 carries the same SCNS number across Florida public institutions and SCNS equivalency governs transfer. As an upper-division course it does not appear in A.A. programmes. Note that some Florida state colleges offer it within Bachelor of Applied Science or Bachelor of Science programmes in information technology — Pasco-Hernando and Seminole State both appear in the statewide inventory — so it is available outside the state university system, which matters for place-bound students. The usual caveat applies: equivalency moves the credit, and the receiving department decides what requirement it satisfies.

Course format and workload

Three credit hours, approximately 45 contact hours. Delivery varies considerably: some institutions teach it as a lecture course with case studies, others build in substantial virtual laboratory work. Online delivery is common and works well given that the laboratory environments are virtualised anyway. Assessment typically combines examinations, laboratory exercises, a risk assessment or policy writing project, and current-events analysis. Expect six to nine hours a week outside class.

Practical advice specific to this course: build a home laboratory. A virtualisation platform on an ordinary laptop, two or three virtual machines, and an isolated network cost nothing and are worth more than any textbook chapter. The single most reliable predictor of who gets hired out of a security programme is who has actually configured, broken and fixed things themselves.

⚠ Legal and ethical boundary — read this before you experiment

This must be stated plainly because students get it wrong with serious consequences. The techniques taught in this course are illegal to use against systems you do not own or have written authorisation to test. Unauthorised access to a computer system is a federal offence under the Computer Fraud and Abuse Act and a state offence under Florida law, and the fact that you were curious, that you did no damage, or that you were studying security is not a defence. Institutional acceptable-use policies apply in addition, and a student who scans their university's network without permission can face expulsion independently of any criminal exposure.

"Authorised" means written, specific, and from someone with actual authority to grant it. Verbal permission from a friend who administers a server is not adequate. Use the deliberately vulnerable practice environments listed above; they exist precisely so that this skill can be developed legally, and employers recognise them.

Certification pathway

This course maps closely onto CompTIA Security+, which is the standard entry-level credential in the field and is a hiring requirement for many defence-adjacent roles. Students should consider sitting it near the end of the course while the material is current — the overlap is high enough that the additional preparation is modest, and the credential is often what gets a résumé past an initial screen. ISC2's Certified in Cybersecurity is a lower-cost alternative entry point. Longer term, the CISSP requires five years of experience and is the career-stage credential.

AI Integration

Security is one of the few fields where AI has changed both sides of the contest simultaneously, and the course is a good place to think clearly about what has actually shifted and what has not.

On the defensive side, the applications are real and now routine. Anomaly detection over network traffic, authentication events and endpoint telemetry catches patterns that rule-based systems miss. Automated triage in security operations centres addresses a genuine crisis — analysts face alert volumes that no human team can review, and the resulting alert fatigue is itself a security failure, since the alert that mattered was in the queue nobody got to. Machine learning-driven email filtering, malware classification and user behaviour analytics are all standard. Students entering security operations will work alongside these systems from day one.

The limitations are the ones the course's risk material prepares you to articulate. Security is adversarial, which breaks the assumption most machine learning rests on — that future data resembles training data. Attackers observe what is detected and change it. Models can be evaded deliberately, and can be attacked directly through poisoned training data. And the base rate problem is severe: genuine attacks are rare relative to normal activity, so even a highly accurate classifier generates false positives in volume, which is why triage rather than detection is the actual bottleneck.

On the offensive side, the change is mostly one of cost and scale rather than capability. Phishing is the clearest case and it matters for this course's human-factors unit: the classic advice to spot phishing by poor grammar and awkward phrasing is now obsolete, because generating fluent, contextually appropriate, personally targeted messages at scale is trivial. Voice cloning has made pretexting calls substantially more convincing, and there are documented cases of synthetic audio and video used successfully in payment fraud. The defensive consequence is a shift away from teaching people to detect deception and toward process controls that do not depend on detection — out-of-band verification, callbacks to independently obtained numbers, dual authorisation for payment changes, and phishing-resistant authentication such as hardware security keys. This is a genuinely important update to the standard awareness-training model and students should understand why it follows.

AI systems are also a new attack surface, which belongs in a foundations course now. Organisations are deploying models with access to internal data and, increasingly, the ability to take actions. That introduces exposures the traditional control catalogue does not cover cleanly: prompt injection, in which instructions embedded in data the model processes cause it to act against its operator's intent; training data poisoning; model and data extraction; and the general problem that a system which follows instructions from untrusted content is difficult to secure by conventional means. A student who understands the CIA triad has the right framework to reason about these, and asking which property is violated by a given AI attack is a good exercise.

For coursework, language models are a good tutor and an unreliable authority. They explain concepts well, generate practice scenarios, help draft a policy document, and assist with scripting and log analysis. They also confidently misstate technical detail, invent CVE numbers, misattribute techniques, and give configuration advice that is subtly insecure — recommending a deprecated cipher suite, an over-permissive rule, or a pattern that was best practice five years ago. Security guidance must be verified against primary sources — NIST publications, vendor documentation, CISA advisories and the CVE database are all authoritative and freely available. In a field where the cost of acting on wrong information is a breach, this is not a formality.


Generated September 5, 2026 · Updated September 5, 2026