Information Security Management
ISM3323 — ISM3323
← Course Modules
Course Description
Information Security Management recognises that information security in the modern organization is both a management and a technology issue, and that technology alone cannot address all the security issues. The course prepares students for management and control of security of information systems in organizations and prepares students to make informed decisions regarding administration of information security infrastructure.
Within the SCNS taxonomy, ISM is the Information Systems Management prefix. The University of West Florida publishes this at 3 semester hours through the Department of Business Administration, College of Business. It is offered at approximately 2 Florida institutions.
⚠ This is the only course in the ISM prefix with an alternative route in. UWF publishes ISM 3011 OR COP 2253 — the second being a programming course. Every other ISM course requires ISM3011 and nothing else. The exception exists because security recruits from both the business and the computing side, and it is worth knowing if you are arriving from computer science.
The framing sentence is the whole argument of the course: technology alone cannot address all the security issues. That is not a soft claim — it is the documented reality of how organisations are actually breached. Phishing, credential reuse, misconfiguration, unpatched systems and insider error account for the substantial majority of incidents, and none of them is a failure of cryptography.
⚠ Security management is unglamorous and it is where the leverage is. Asset inventory, access review, patch discipline, backup testing and vendor risk are the controls that prevent most incidents, and they fail through organisational neglect rather than technical difficulty. A student who learns to run them well is more useful to most employers than one who can name attack techniques.
⚠ The contact-hour figure is derived — the University of West Florida publishes none
UWF's catalog publishes a credit value in semester hours, the college and department, and prerequisites. It does not publish contact hours, a lecture and laboratory split, or terms of offering for any course. Every contact-hour value in a UWF guide in this repository is derived. The figure applies the standard lecture convention of 15 contact hours per credit, giving 45 hours for 3 semester hours. ⚠ Note that ISM courses are project-heavy, and scheduled contact hours understate the real time commitment considerably — budget for project work outside class. Confirm the meeting schedule and delivery mode with the department.
Learning Outcomes
Required Outcomes
- Describe the scope of information security and its business role.
- Apply the confidentiality, integrity, and availability model.
- Describe threats, vulnerabilities, attacks, and their relationships.
- Describe the major categories of threat actor and their motivations.
- Describe common attack types including social engineering and phishing.
- Describe malware categories and ransomware in particular.
- Describe the components of an information security programme.
- Describe security governance and the roles and responsibilities within it.
- Develop and evaluate information security policy.
- Distinguish policy, standard, procedure, and guideline.
- Describe access control models and the principle of least privilege.
- Describe identity and access management including authentication factors.
- Describe security awareness training and evaluate its effectiveness.
- Describe physical and environmental security controls.
- Describe network and system security controls in management terms.
- Describe cryptography and its business applications in outline.
- Describe security frameworks including NIST CSF and ISO 27001.
- Describe regulatory drivers including HIPAA, GLBA, PCI-DSS, and FERPA.
- Describe security metrics and reporting to management.
- Describe vendor and third-party risk management.
- Make and justify an informed decision about security infrastructure.
Optional Outcomes
- Apply the material to a real organisation or a case study.
- Use AI-assisted tools appropriately and verify their output.
- Communicate technical findings to a non-technical audience.
- Work effectively in a project team with defined roles.
- Build a portfolio artefact suitable for showing an employer.
Major Topics
Required Topics
- Scope and business role of security
- Confidentiality, integrity, availability
- Threats, vulnerabilities, attacks
- Threat actors and motivations
- Social engineering and phishing
- Malware and ransomware
- Components of a security programme
- Security governance and roles
- Security policy development
- Policy, standard, procedure, guideline
- Access control models and least privilege
- Identity and access management
- Security awareness training
- Physical and environmental security
- Network and system controls
- Cryptography in outline
- NIST CSF and ISO 27001
- HIPAA, GLBA, PCI-DSS, FERPA
- Security metrics and reporting
- Third-party and vendor risk
- Security infrastructure decisions
Optional Topics
- Applied case studies and live organisations
- AI-assisted tooling and its verification
- Communicating findings to non-technical stakeholders
- Team project practice
- Portfolio development
Resources & Tools
- The text the instructor assigns — Whitman and Mattord's Management of Information Security and Principles of Information Security are the standards in this space and are written for exactly this course.
- NIST Cybersecurity Framework and the SP 800 series (nist.gov) — free; the actual reference documents that working security programmes are built on, particularly SP 800-53 and SP 800-171. Reading a real control catalogue once is worth several textbook chapters.
- CIS Critical Security Controls (cisecurity.org) — free; a prioritised, practical control list, and the most useful starting point for a small organisation.
- Verizon Data Breach Investigations Report — free, annual; evidence on how breaches actually happen, which repeatedly contradicts intuition and is the best antidote to security theatre.
- CISA advisories and the Known Exploited Vulnerabilities catalogue — free; what is being exploited right now.
- CompTIA Security+ objectives — free to download; a good self-check on coverage even if you do not sit the exam.
- The UWF library's business databases — included in enrolment; practitioner sources such as Gartner and industry reports are behind paywalls a student already has, and most never find out.
- LinkedIn Learning — frequently free through UWF or a Florida public library card; strong on specific tools, weak on judgement. Use it for the software, not the thinking.
Career Pathways
- Business or systems analyst (SOC 15-1211, computer systems analyst) — the most common destination for this major, and the role this prefix is most directly built for: translating business needs into system requirements.
- Data analyst and business intelligence analyst (SOC 15-2051, data scientist; SOC 13-1111, management analyst) — the fastest-growing destination, and the reason the analytics courses in this prefix matter.
- Information security analyst (SOC 15-1212) — strong demand and strong pay in Florida, particularly around defence contracting in the Panhandle and Space Coast. Note that this prefix teaches security management, not penetration testing — a real and separate career.
- Database administrator and data engineer (SOC 15-1242, 15-1243).
- IT project manager — commonly entered after several years as an analyst; PMP or CAPM certification is the usual credential.
- ERP functional consultant — SAP, Oracle, Workday, Microsoft Dynamics; a well-paid path that is under-advertised to undergraduates.
- ⚠ Florida employer landscape: defence and aerospace contractors (Lockheed Martin, Northrop Grumman, L3Harris, and the Navy presence around Pensacola), healthcare systems (AdventHealth, Orlando Health, BayCare, Baptist, Ascension Sacred Heart), hospitality and theme parks (Disney, Universal, the cruise lines out of Miami, Port Canaveral and Tampa — all of which run substantial IT organisations), financial services (Raymond James in St. Petersburg, Fidelity in Jacksonville), logistics, and state and county government.
- ⚠ Security clearance is a genuine career asset in this state. Northwest Florida's defence concentration means clearable candidates have access to roles others do not — worth knowing early, because the process is slow and starts with an employer sponsoring you.
AI Integration
Information systems is one of the fields where generative AI has changed working practice fastest, and pretending otherwise would not serve a student. The honest position is that these tools are genuinely useful, genuinely unreliable, and that the professional remains accountable for the output regardless of what produced it.
- Where AI tools help in this domain: drafting and explaining code and SQL, generating test data, summarising documentation and standards, producing first-draft requirements and process descriptions, writing spreadsheet and BI formulas, and explaining an unfamiliar error message — which is a large share of what stalls a beginner.
- ⚠ Where they fail, specifically: they invent plausible functions, libraries, and API endpoints that do not exist; they produce code that runs and is subtly wrong; they are confidently wrong about anything niche, recent, or organisation-specific; and they cannot know your data, your business rules, or your regulatory constraints unless you tell them.
- ⚠⚠ The failure mode that matters most here is a wrong answer that looks right. A query that returns rows is not a query that returns correct rows. Verify against known values before you trust an analysis, and be especially careful with joins, filters, date handling, and anything involving aggregation.
- ⚠⚠⚠ Never paste confidential, personal, or regulated data into a public AI tool. Organisational data, customer records, health information, and anything under FERPA, HIPAA, GLBA or PCI-DSS must not leave a controlled environment. This is a genuine and common way that early-career employees cause serious incidents, and "I did not know" is not a defence that helps anyone. Use synthetic or anonymised data for anything you take outside a sanctioned system.
- Academic integrity: the course policy governs, and policies differ. Some instructors encourage AI use with disclosure, some restrict it to specified tasks, some prohibit it. Read the syllabus and ask if it is unclear — assuming is how students end up in an integrity process.
- ⚠ The professional argument for learning without it first is real, not moralising. If you cannot read and evaluate the output, you cannot catch it when it is wrong — and an employer is paying for the judgement, not the typing. Use AI to go faster on things you understand; do the learning yourself.
- Cite and disclose what you used, when the policy asks. This is becoming a normal professional expectation as well as an academic one.
Special Information
⚠⚠ ISM3011 is the gateway to the entire prefix
- Every undergraduate ISM course at UWF except
ISM3011 itself requires it. ISM3116, ISM3323, ISM4113, ISM4320, ISM4321, ISM4400, ISM4481 and ISM4483 all name it. Nothing else in the prefix opens without it.
- ⚠ That makes it a single point of failure in your schedule. Delaying or failing
ISM3011 delays everything downstream, and there is no alternative route around it. Take it as early as you are eligible.
- Only
ISM3323 offers an alternative — it accepts ISM 3011 OR COP 2253, a programming route. It is the sole exception in the prefix.
- ⚠
ISM3011 itself has an unusual prerequisite: not a course, but completion of 45 hours of college coursework. See the note on standing requirements below.
⚠⚠ UWF runs a cybersecurity sequence inside a BUSINESS prefix — know what that means
- Three ISM courses form a security sequence:
ISM3323 Information Security Management, ISM4320 Legal, Ethical, and Human Aspects of Cybersecurity, and ISM4321 Cybersecurity Risk Management. All three sit in the Department of Business Administration, College of Business.
- ⚠⚠ This is security management, not security engineering. The sequence teaches governance, risk, policy, law, human factors and incident planning. It does not teach penetration testing, exploit development, malware analysis, or network defence operations — those are computer science and IT courses, and at UWF they live under different prefixes.
- Neither half is the "real" one. Organisations are breached through unpatched systems and through untrained people in roughly equal measure, and the majority of security work in a large organisation is governance, audit and risk rather than hands-on-keyboard. But a student who wants the technical career needs the technical courses, and this sequence will not supply them.
- ⚠ The strongest position is both. A graduate who can read a risk register and a packet capture is unusually valuable, and the combination is what security leadership roles actually require.
- Practical step: check whether UWF's computer science or IT programmes will let you take networking and security technical electives alongside this sequence, and ask early — prerequisite chains in those prefixes are long.
⚠ Northwest Florida is a defence region, and that shapes this career
- Pensacola and the surrounding area carry a substantial military and defence-contracting presence — NAS Pensacola, NAS Whiting Field, Eglin and Hurlburt Field, and the contractors that serve them. Cybersecurity demand there is real and sustained.
- ⚠⚠ Many of those roles require a security clearance, which you cannot obtain on your own — an employer must sponsor it, and the process takes months. Knowing this early changes how you approach internships, because a sponsored internship is the usual on-ramp.
- Clearance eligibility is affected by things students do not expect: significant debt, foreign contacts, and drug use including cannabis, which remains federally prohibited regardless of state law. This is stated as fact, not as advice about how to live.
- DoD 8140 (formerly 8570) specifies baseline certifications for defence cybersecurity roles — CompTIA Security+ is the common entry requirement. Having it before you graduate is a genuine advantage in this region.
- Florida's other security demand centres: healthcare systems (HIPAA-driven), financial services in Tampa Bay and Jacksonville, the cruise lines, and state and county government.
Certifications worth knowing about
- ⚠ A degree and a certification do different jobs. The degree is the durable credential; certifications are current, specific, and expire. Employers in this field ask for both, and neither substitutes for the other.
- Analytics and data: Microsoft Power BI Data Analyst (PL-300), Tableau Desktop Specialist, Google Data Analytics, AWS and Azure data certifications. Several have free or heavily discounted student pricing — ask the College of Business.
- Security: CompTIA Security+ is the standard entry credential and is frequently a hard requirement for defence-adjacent work under DoD 8570/8140; CISSP and CISM are management-level and require documented experience.
- Project and process: CAPM, PMP, and the Scrum credentials.
- ⚠ Do not collect certifications instead of building things. A portfolio of real projects — a dashboard, a database, an analysis with a written recommendation — outperforms a list of badges in almost every hiring conversation in this field.
Transfer, articulation, and how Florida course levels work
In the Florida Statewide Course Numbering System the first digit is the level: 1 and 2 are lower division, 3 and 4 upper division, 5 and above graduate. ⚠ A lower-division course generally cannot satisfy an upper-division requirement, which matters in this prefix — ISM2000 and ISM3011 both introduce information systems, and only the second is upper division.
⚠⚠ Business programmes add a layer that SCNS does not. Many Florida business colleges are AACSB accredited, and AACSB programmes commonly limit how much upper-division business coursework may transfer in — frequently requiring a substantial share to be taken in residence. A course can articulate under SCNS and still not count toward the major. Check the receiving programme's residency rule before you rely on a transfer.
Many business programmes also impose an admission-to-the-major step with its own grade point requirement, and a minimum grade in each core course. Confirm both against your own catalog year.
Course format and position in the curriculum
- Lecture with substantial project and applied work. ⚠ ISM courses are consistently more time-consuming than their credit value suggests, because software work expands to fill the debugging available.
- ⚠ No "permission is required" marking appears anywhere in the ISM prefix, and no fee notices — enrolment is gated by
ISM3011 and by standing.
- Ask about delivery mode. UWF offers substantial online provision in the College of Business, and an online section of a project-based course demands more self-management, not less.
- UWF publishes no contact hours or terms of offering. A course offered in one term only will delay a sequence by a full year if missed — confirm with the department.
ISM3323 is 3 semester hours at the University of West Florida.