Cybersecurity Risk Management
ISM4321 — ISM4321
← Course Modules
Course Description
Cybersecurity Risk Management focuses on the application of risk management theory and principles to information security policy. UWF states that an additional major area of focus is incident response and contingency planning consisting of incident response planning, disaster recovery planning, and business continuity planning.
Within the SCNS taxonomy, ISM is the Information Systems Management prefix. The University of West Florida publishes this at 3 semester hours through the Department of Business Administration, College of Business. It is offered at approximately 4 Florida institutions.
⚠ This is the most directly employable course in the ISM security sequence, because risk management and incident response are what organisations actually hire security staff to do. Governance, risk and compliance — "GRC" — is a large and growing share of the security job market, and it is reachable from a business degree in a way that security engineering is not.
Risk management is where security stops being a wish list and becomes a decision. Every control costs money and friction; no organisation can implement all of them; the question is always which risks to treat, which to transfer, which to accept, and how to defend that choice to someone who signs the budget. Learning to make and justify that trade-off is the point.
⚠ The contingency planning half is the part students underestimate and employers value most. An incident response plan that has never been tested is a document, not a capability — and the single commonest finding after a serious incident is that the plan existed and nobody had rehearsed it. The same is true of backups: an untested backup is an assumption.
Ransomware has made this material urgent rather than theoretical. Florida organisations — municipalities, school districts, hospitals and small businesses among them — have been hit repeatedly, and the difference between a bad week and an existential event is almost entirely whether recovery had been planned and practised.
⚠ The contact-hour figure is derived — the University of West Florida publishes none
UWF's catalog publishes a credit value in semester hours, the college and department, and prerequisites. It does not publish contact hours, a lecture and laboratory split, or terms of offering for any course. Every contact-hour value in a UWF guide in this repository is derived. The figure applies the standard lecture convention of 15 contact hours per credit, giving 45 hours for 3 semester hours. ⚠ Note that ISM courses are project-heavy, and scheduled contact hours understate the real time commitment considerably — budget for project work outside class. Confirm the meeting schedule and delivery mode with the department.
Learning Outcomes
Required Outcomes
- Describe risk management theory and its application to information security.
- Define threat, vulnerability, likelihood, impact, and risk precisely.
- Describe the risk management process from identification to monitoring.
- Conduct asset identification, classification, and valuation.
- Conduct threat identification and vulnerability assessment.
- Apply qualitative risk assessment methods.
- Apply quantitative risk assessment including SLE, ARO, and ALE.
- Compare qualitative and quantitative approaches and their limits.
- Describe risk treatment options: mitigate, transfer, avoid, accept.
- Evaluate the cost-effectiveness of a proposed control.
- Describe residual risk and risk acceptance and who may accept it.
- Describe risk registers and risk reporting to management.
- Describe cyber insurance and what it does and does not cover.
- Relate risk management to information security policy development.
- Describe risk management frameworks including NIST RMF and ISO 27005.
- Describe incident response planning and its phases.
- Describe incident detection, triage, containment, and eradication.
- Describe post-incident review and lessons-learned processes.
- Describe disaster recovery planning, RTO, and RPO.
- Describe business continuity planning and business impact analysis.
- Describe testing and exercising of contingency plans.
- Describe legal and notification obligations following an incident.
Optional Outcomes
- Apply the material to a real organisation or a case study.
- Use AI-assisted tools appropriately and verify their output.
- Communicate technical findings to a non-technical audience.
- Work effectively in a project team with defined roles.
- Build a portfolio artefact suitable for showing an employer.
Major Topics
Required Topics
- Risk management theory and application
- Threat, vulnerability, likelihood, impact
- The risk management process
- Asset identification and valuation
- Threat and vulnerability assessment
- Qualitative risk assessment
- Quantitative risk assessment: SLE, ARO, ALE
- Comparing assessment approaches
- Risk treatment options
- Cost-effectiveness of controls
- Residual risk and acceptance
- Risk registers and reporting
- Cyber insurance
- Risk and security policy
- NIST RMF and ISO 27005
- Incident response planning
- Detection, triage, containment, eradication
- Post-incident review
- Disaster recovery, RTO and RPO
- Business continuity and business impact analysis
- Testing and exercising plans
- Legal and notification obligations
Optional Topics
- Applied case studies and live organisations
- AI-assisted tooling and its verification
- Communicating findings to non-technical stakeholders
- Team project practice
- Portfolio development
Resources & Tools
- The text the instructor assigns — Whitman and Mattord's Management of Information Security and Principles of Incident Response and Disaster Recovery are written for this course specifically.
- NIST SP 800-30 (risk assessment), SP 800-37 (RMF), and SP 800-61 (incident handling) — free; these are the actual working documents, and SP 800-61 in particular is short enough to read properly.
- NIST SP 800-34 (contingency planning) — free; the template most organisational continuity plans descend from.
- CISA tabletop exercise packages — free; ready-made scenarios you can actually run, and the fastest way to understand why untested plans fail.
- CISA StopRansomware guide — free; current, practical, and directly relevant to the threat driving most of this material.
- FAIR (Factor Analysis of Information Risk) — introductory material is free; the leading attempt to put quantitative rigour into cyber risk, and worth knowing exists.
- Florida Digital Service and state agency security rules — free; how this is governed for Florida public bodies.
- The UWF library's business databases — included in enrolment; practitioner sources such as Gartner and industry reports are behind paywalls a student already has, and most never find out.
- LinkedIn Learning — frequently free through UWF or a Florida public library card; strong on specific tools, weak on judgement. Use it for the software, not the thinking.
Career Pathways
- Business or systems analyst (SOC 15-1211, computer systems analyst) — the most common destination for this major, and the role this prefix is most directly built for: translating business needs into system requirements.
- Data analyst and business intelligence analyst (SOC 15-2051, data scientist; SOC 13-1111, management analyst) — the fastest-growing destination, and the reason the analytics courses in this prefix matter.
- Information security analyst (SOC 15-1212) — strong demand and strong pay in Florida, particularly around defence contracting in the Panhandle and Space Coast. Note that this prefix teaches security management, not penetration testing — a real and separate career.
- Database administrator and data engineer (SOC 15-1242, 15-1243).
- IT project manager — commonly entered after several years as an analyst; PMP or CAPM certification is the usual credential.
- ERP functional consultant — SAP, Oracle, Workday, Microsoft Dynamics; a well-paid path that is under-advertised to undergraduates.
- ⚠ Florida employer landscape: defence and aerospace contractors (Lockheed Martin, Northrop Grumman, L3Harris, and the Navy presence around Pensacola), healthcare systems (AdventHealth, Orlando Health, BayCare, Baptist, Ascension Sacred Heart), hospitality and theme parks (Disney, Universal, the cruise lines out of Miami, Port Canaveral and Tampa — all of which run substantial IT organisations), financial services (Raymond James in St. Petersburg, Fidelity in Jacksonville), logistics, and state and county government.
- ⚠ Security clearance is a genuine career asset in this state. Northwest Florida's defence concentration means clearable candidates have access to roles others do not — worth knowing early, because the process is slow and starts with an employer sponsoring you.
AI Integration
Information systems is one of the fields where generative AI has changed working practice fastest, and pretending otherwise would not serve a student. The honest position is that these tools are genuinely useful, genuinely unreliable, and that the professional remains accountable for the output regardless of what produced it.
- Where AI tools help in this domain: drafting and explaining code and SQL, generating test data, summarising documentation and standards, producing first-draft requirements and process descriptions, writing spreadsheet and BI formulas, and explaining an unfamiliar error message — which is a large share of what stalls a beginner.
- ⚠ Where they fail, specifically: they invent plausible functions, libraries, and API endpoints that do not exist; they produce code that runs and is subtly wrong; they are confidently wrong about anything niche, recent, or organisation-specific; and they cannot know your data, your business rules, or your regulatory constraints unless you tell them.
- ⚠⚠ The failure mode that matters most here is a wrong answer that looks right. A query that returns rows is not a query that returns correct rows. Verify against known values before you trust an analysis, and be especially careful with joins, filters, date handling, and anything involving aggregation.
- ⚠⚠⚠ Never paste confidential, personal, or regulated data into a public AI tool. Organisational data, customer records, health information, and anything under FERPA, HIPAA, GLBA or PCI-DSS must not leave a controlled environment. This is a genuine and common way that early-career employees cause serious incidents, and "I did not know" is not a defence that helps anyone. Use synthetic or anonymised data for anything you take outside a sanctioned system.
- Academic integrity: the course policy governs, and policies differ. Some instructors encourage AI use with disclosure, some restrict it to specified tasks, some prohibit it. Read the syllabus and ask if it is unclear — assuming is how students end up in an integrity process.
- ⚠ The professional argument for learning without it first is real, not moralising. If you cannot read and evaluate the output, you cannot catch it when it is wrong — and an employer is paying for the judgement, not the typing. Use AI to go faster on things you understand; do the learning yourself.
- Cite and disclose what you used, when the policy asks. This is becoming a normal professional expectation as well as an academic one.
Special Information
⚠⚠ ISM3011 is the gateway to the entire prefix
- Every undergraduate ISM course at UWF except
ISM3011 itself requires it. ISM3116, ISM3323, ISM4113, ISM4320, ISM4321, ISM4400, ISM4481 and ISM4483 all name it. Nothing else in the prefix opens without it.
- ⚠ That makes it a single point of failure in your schedule. Delaying or failing
ISM3011 delays everything downstream, and there is no alternative route around it. Take it as early as you are eligible.
- Only
ISM3323 offers an alternative — it accepts ISM 3011 OR COP 2253, a programming route. It is the sole exception in the prefix.
- ⚠
ISM3011 itself has an unusual prerequisite: not a course, but completion of 45 hours of college coursework. See the note on standing requirements below.
⚠⚠ UWF runs a cybersecurity sequence inside a BUSINESS prefix — know what that means
- Three ISM courses form a security sequence:
ISM3323 Information Security Management, ISM4320 Legal, Ethical, and Human Aspects of Cybersecurity, and ISM4321 Cybersecurity Risk Management. All three sit in the Department of Business Administration, College of Business.
- ⚠⚠ This is security management, not security engineering. The sequence teaches governance, risk, policy, law, human factors and incident planning. It does not teach penetration testing, exploit development, malware analysis, or network defence operations — those are computer science and IT courses, and at UWF they live under different prefixes.
- Neither half is the "real" one. Organisations are breached through unpatched systems and through untrained people in roughly equal measure, and the majority of security work in a large organisation is governance, audit and risk rather than hands-on-keyboard. But a student who wants the technical career needs the technical courses, and this sequence will not supply them.
- ⚠ The strongest position is both. A graduate who can read a risk register and a packet capture is unusually valuable, and the combination is what security leadership roles actually require.
- Practical step: check whether UWF's computer science or IT programmes will let you take networking and security technical electives alongside this sequence, and ask early — prerequisite chains in those prefixes are long.
⚠⚠ Two ideas from this course that are worth carrying into any job
- An untested plan is not a plan. Backups that have never been restored, response plans never rehearsed, and contact lists never verified all fail at the moment they are needed. This is the single most reliable finding in post-incident reviews across the industry.
- ⚠ Quantitative risk figures are more fragile than they look. An annualised loss expectancy is the product of two estimates, each uncertain, and presenting it to three decimal places implies a precision that does not exist. Use the method; state the assumptions; do not let the arithmetic launder a guess into a fact.
- Risk acceptance is a decision that belongs to management, not to security staff. The professional job is to surface the risk clearly and let the accountable person decide — and to record that they did.
⚠ Northwest Florida is a defence region, and that shapes this career
- Pensacola and the surrounding area carry a substantial military and defence-contracting presence — NAS Pensacola, NAS Whiting Field, Eglin and Hurlburt Field, and the contractors that serve them. Cybersecurity demand there is real and sustained.
- ⚠⚠ Many of those roles require a security clearance, which you cannot obtain on your own — an employer must sponsor it, and the process takes months. Knowing this early changes how you approach internships, because a sponsored internship is the usual on-ramp.
- Clearance eligibility is affected by things students do not expect: significant debt, foreign contacts, and drug use including cannabis, which remains federally prohibited regardless of state law. This is stated as fact, not as advice about how to live.
- DoD 8140 (formerly 8570) specifies baseline certifications for defence cybersecurity roles — CompTIA Security+ is the common entry requirement. Having it before you graduate is a genuine advantage in this region.
- Florida's other security demand centres: healthcare systems (HIPAA-driven), financial services in Tampa Bay and Jacksonville, the cruise lines, and state and county government.
Certifications worth knowing about
- ⚠ A degree and a certification do different jobs. The degree is the durable credential; certifications are current, specific, and expire. Employers in this field ask for both, and neither substitutes for the other.
- Analytics and data: Microsoft Power BI Data Analyst (PL-300), Tableau Desktop Specialist, Google Data Analytics, AWS and Azure data certifications. Several have free or heavily discounted student pricing — ask the College of Business.
- Security: CompTIA Security+ is the standard entry credential and is frequently a hard requirement for defence-adjacent work under DoD 8570/8140; CISSP and CISM are management-level and require documented experience.
- Project and process: CAPM, PMP, and the Scrum credentials.
- ⚠ Do not collect certifications instead of building things. A portfolio of real projects — a dashboard, a database, an analysis with a written recommendation — outperforms a list of badges in almost every hiring conversation in this field.
Transfer, articulation, and how Florida course levels work
In the Florida Statewide Course Numbering System the first digit is the level: 1 and 2 are lower division, 3 and 4 upper division, 5 and above graduate. ⚠ A lower-division course generally cannot satisfy an upper-division requirement, which matters in this prefix — ISM2000 and ISM3011 both introduce information systems, and only the second is upper division.
⚠⚠ Business programmes add a layer that SCNS does not. Many Florida business colleges are AACSB accredited, and AACSB programmes commonly limit how much upper-division business coursework may transfer in — frequently requiring a substantial share to be taken in residence. A course can articulate under SCNS and still not count toward the major. Check the receiving programme's residency rule before you rely on a transfer.
Many business programmes also impose an admission-to-the-major step with its own grade point requirement, and a minimum grade in each core course. Confirm both against your own catalog year.
Course format and position in the curriculum
- Lecture with substantial project and applied work. ⚠ ISM courses are consistently more time-consuming than their credit value suggests, because software work expands to fill the debugging available.
- ⚠ No "permission is required" marking appears anywhere in the ISM prefix, and no fee notices — enrolment is gated by
ISM3011 and by standing.
- Ask about delivery mode. UWF offers substantial online provision in the College of Business, and an online section of a project-based course demands more self-management, not less.
- UWF publishes no contact hours or terms of offering. A course offered in one term only will delay a sequence by a full year if missed — confirm with the department.
ISM4321 is 3 semester hours at the University of West Florida.