City University of Hong Kong · FACULTY OF INFORMATION TECHNOLOGY

IS6523 Information Systems Infrastructure and Security Management

- one subject, every graph, every model, every mark
10 Chapters61-page Bible
Our own words - no uploaded lecturer files
Updated for this semester
The Complete Exam Bible · Semester A 2026/27

IS6523 Overview

Information Systems Infrastructure and Security Management
— Name the asset, name the threat, then price the control and say why a business would fund it.
  • City University of Hong Kong
  • Semester A, 2026/27
  • Department of Information Systems
  • Postgraduate, three credit units
  • Two hour written examination

What this course is actually asking you to do

The published aim is to examine the key infrastructural and security issues involved in electronic commerce transactions, with a managerial perspective adopted throughout, covering both the electronic payment infrastructure and the transactional security infrastructure.

  • Assessed by A two hour written examination worth half the mark, a group security or audit analysis project, an individual research report and class activity.
  • The pass condition The catalogue publishes a minimum of 25 per cent in continuous assessment and 25 per cent in the examination, and the teaching plan states both have to be passed.
  • The skill being tested Choosing a control for a described business situation and defending the choice on what it costs against what it saves.
  • Hardest step The project's risk and countermeasure section carries the largest block of its marks, and groups routinely spend that time on the company profile instead.
  • Where to confirm Weights, deadlines and submission settings are controlled by the course site on Canvas.
IS6523 · City University of Hong Kong
An independent, AskSia-authored study guide. AskSia is not affiliated with, endorsed by, or sponsored by City University of Hong Kong; the course code and name are used for identification only.
Assessment

How IS6523 is assessed

ComponentWeightFormat
Class Activity5%Class exercises and group discussion across the taught sessions, assessing understanding of the topics and the ability to apply it
Individual Assignment15%A written report on new developments related to an existing topic, with critical analysis and the impact on business organisations
Project30%A group of about four to six students produces a security or audit analysis report with findings and recommendations, plus a twenty minute presentation
Final Examination50%One written examination of two hours, assessing competence in the taught subjects

The course syllabus lists these four tasks and they total one hundred per cent, split as fifty per cent continuous assessment and fifty per cent examination. Two further points matter. The University catalogue entry publishes a minimum continuous assessment passing requirement of twenty five per cent and a minimum examination passing requirement of twenty five per cent, and the course teaching plan states that both the coursework and the examination have to be passed to pass the course overall; those are two conditions rather than one aggregate. The catalogue also calls its own assessment figures indicative and directs readers to the detailed course information. The teaching materials available here are from an earlier offering, so confirm the split of the class activity mark, and every date, on the current Canvas course site.

Assessment structure

5%Class activity15%Individual assignment30%Project50%Final examinationContinuous assessment 50% on the left, examination 50% on the right

Both halves carry a published minimum passing requirement of 25 per cent, and the course teaching plan states that the coursework and the examination each have to be passed.

Contents · every chapter, one map

What IS6523 covers

Ten chapters follow the taught session sequence from the definition of information security through attack methods, cryptography, payment infrastructure, firewalls, intrusion detection, risk economics, law and governance, auditing and continuity planning.

01

Information Security, the CIA Triad and the Security Gap

the definition the course opens with · confidentiality, integrity and availability as three kinds of loss · security management as a gap between practice and policy · the four business functions security performs
02

Attack Methods and the Threat Landscape

threat, vulnerability, attack and threat agent kept apart · the named attack families and what each exploits · denial of service and the handshake it abuses · the threat categories with no attacker behind them
03

Encryption, Keys and Digital Signatures

substitution, transposition and exclusive-or · symmetric against asymmetric keys · the hybrid envelope · hashes, digital signatures and non-repudiation · public key infrastructure and certificate authorities
04

Distributed Ledgers and Electronic Payment Systems

blocks, hash pointers and identical copies on every node · transparency and incorruptibility as properties with costs · the four criteria a payment system is judged on · the instruments and the certificate authorities behind them
05

Access Control, Firewalls and Perimeter Architecture

identification, authentication, authorisation and accountability · mandatory, nondiscretionary and discretionary models · four firewall generations and what each can observe · bastion, screened host and screened subnet · virtual private networks and wireless footprint
06

Intrusion Detection, Scanning and Biometric Controls

network against host placement · signature against anomaly and the clipping level · port ranges, footprinting and fingerprinting · the lawful conditions on a packet sniffer · Type I and Type II error and the crossover rate
07

Managing IT Risk and the Economics of Controls

knowing the asset and knowing the threat · identification, analysis, evaluation and treatment · likelihood, uncertainty and the relative risk formula · five treatment strategies · loss expectancy and the cost benefit comparison
08

Law, Ethics and IT Governance in Information Security

law, policy and ethics and the sanction attached to each · international agreements and their enforceability · the six data protection principles · governance as a board responsibility · a control framework beside a reporting statute
09

Auditing Systems, Management and Application Controls

collecting and evaluating evidence for an independent opinion · internal, external and independent audits · management controls as layers around application controls · boundary, input, communications, processing, database and output · check digits and the errors they miss
10

Security Planning, Continuity and Implementation

policy, standard and practice · governance outcomes and the improvement cycle · incident, disaster and continuity plans · hot, warm and cold sites · conversion strategies and change as a control

That managerial clause is the whole shape of the course. Eleven taught sessions run from a definition of information security to project management for a security programme, and almost none of the assessment rewards being able to describe a technology.

What it rewards is taking a business situation, naming what is at risk in it, naming the mechanism that would attack it, and choosing a control you can defend on cost.

How the sessions build on each other

The first four sessions fix the vocabulary that everything else borrows: the confidentiality, integrity and availability characteristics; the difference between a threat, a vulnerability and an attack; symmetric and asymmetric keys; and what a hash proves.

The middle sessions catalogue the controls, with firewalls and perimeter architecture in one and intrusion detection, scanning tools and biometrics in the next, each instrument presented with a stated reach and a stated blind spot.

The later sessions turn managerial: risk quantified in money, law and governance as constraints, information systems auditing as the production of evidence, and the planning cycle that turns a decision into a programme.

The learning outcomes tell you where the weight sits

The syllabus assigns weightings to its five intended learning outcomes, and the largest share goes to applying security management principles and the legal issues in electronic commerce to the design of security policies and operations.

Applying technical concepts and risk management, evaluating audit principles and control frameworks, and evaluating the security of payment infrastructure each carry a fifth, and communicating security solutions to stakeholders carries the remainder. Three of the five are management outcomes, which is the clearest published signal about how to prepare.

Worked example · free

Decide whether a control is worth buying

Q [8 marks]. AskSia-authored practice. A distributor values its order platform at two million dollars. A ransomware event is judged to destroy sixty per cent of that value in lost trading and recovery, and the firm expects such an event once in four years. A managed detection contract costs one hundred and forty thousand dollars a year and would cut the frequency to once in ten years without changing the severity. Should the firm buy it? The marks shown are an AskSia study allocation and are not the University's marking scheme.
  • 2Compute the single loss expectancy from asset value and exposure factor.
  • 3Compute the annualised loss expectancy before and after the control.
  • 2Run the cost benefit comparison and state the recommendation.
  • 1Name the input the conclusion is most sensitive to.
Single loss expectancy is asset value times exposure factor, so two million at sixty per cent is one million two hundred thousand dollars per event. Annualised loss expectancy is that figure times the annualised rate of occurrence: one event in four years is a rate of zero point two five, giving three hundred thousand dollars a year before the control, and one event in ten years is zero point one, giving one hundred and twenty thousand after it. The cost benefit comparison is the pre-control figure minus the post-control figure minus the annualised cost of the safeguard, which is three hundred thousand minus one hundred and twenty thousand minus one hundred and forty thousand, or forty thousand dollars a year in favour. Buy it. The conclusion is most sensitive to the exposure factor, because it multiplies through both annualised figures, and it was estimated rather than measured.
Sia tip — Enter the exposure factor as a decimal before you multiply. Sixty per cent is 0.6, not 60; a factor left as a percentage inflates the single loss expectancy and both annualised figures by a hundred, and the cost benefit sign flips with it.
Glossary

Key terms

Information Security
A considered confidence that an organisation's information exposures and the controls are in balance. The definition is a balance rather than a state of safety, which is why every later topic is a way of making one side of it measurable.
Security Gap
The distance between what an organisation currently does and the standard its policies and standards set. Narrowing it with security tools and countermeasures is what the course means by security management.
Threat
An object, person or other entity standing as a permanent danger to an asset. It exists whether or not anyone acts, which is what separates it from an attack.
Vulnerability
An identified weakness in a controlled system that an attack exploits. Risk identification produces one list of these per information asset.
Non-repudiation
The property that stops a party denying, afterwards, that it took part in a transaction. It is produced by encrypting a message digest with a private key, and the course calls it the foundation of digital signatures.
Demilitarised Zone
A network segment in which it is the firewall, rather than an internal server, that stands exposed to the outside, with further filtering between it and internal systems.
Clipping Level
The boundary of the baseline parameters in an anomaly based detection system. Activity falling outside it triggers a notification to the administrator.
Crossover Error Rate
The threshold at which a biometric system's false reject rate equals its false accept rate. It is the single figure that allows two such systems to be compared.
Annualised Loss Expectancy
The single loss expectancy multiplied by the annualised rate of occurrence, giving the expected yearly loss from one threat against one asset. It is the benefit term in a cost benefit comparison.
Residual Risk
What remains after safeguards have been implemented. The course's stated aim is not an exposure of zero but one matched to the organisation's stated appetite.
Statement of Applicability
The planning document recording which control objectives and controls were selected. It is the durable evidence that an omitted control was a decision rather than an oversight.
FAQ

IS6523 FAQ

How is the mark divided, and does the course have a final examination?

It does. The syllabus divides the mark into four tasks: class activity worth five per cent, an individual assignment worth fifteen, a group project worth thirty, and a final examination worth fifty. That makes the split fifty per cent continuous assessment and fifty per cent examination, and the examination is described as one written paper of two hours assessing competence in the taught subjects.

The catalogue describes its own figures as indicative and points readers to the detailed course information, so confirm the current split on the Canvas course site.

Can a strong project carry a weak examination result?

Not according to the published pass conditions. The University catalogue entry publishes a minimum continuous assessment passing requirement of twenty five per cent and a separate minimum examination passing requirement of twenty five per cent, and the course teaching plan states that both the coursework and the examination have to be passed in order to pass the course overall.

Those are two conditions rather than one total, so coursework and paper each have to clear their own floor before the aggregate matters at all.

What does a two hour written paper actually ask for in a subject this broad?

The course publishes no paper structure, only that the examination is written and runs two hours. What a paper of that length can ask over eleven sessions falls into four shapes: distinguish two terms students collapse, diagnose which control would have caught a described failure, compute a loss expectancy or a cost benefit comparison, and recommend a control for a business situation.

The last of these carries the managerial weight the syllabus says the course adopts throughout, and it needs a named control, the risk it reduces and a funding reason.

Where do the marks concentrate inside the group project?

The project brief publishes its own internal allocation and it is lopsided. Identifying the security risks in each business case and proposing countermeasures carries the largest block, with the business cases themselves close behind and the technical description of the artificial intelligence tools a distant third. The company background and situational analysis carry the smallest block of all.

Groups routinely invert this, which is the most avoidable way to lose marks on a task worth thirty per cent of the course.

How much mathematics does this course contain?

Very little, and all of it is worth knowing exactly because it is the most reliably examinable material in the syllabus. Single loss expectancy is asset value times exposure factor; annualised loss expectancy is that figure times the annualised rate of occurrence; and the cost benefit comparison is the annualised loss expectancy before a control, minus the figure after it, minus the annualised cost of the safeguard.

A relative risk formula combining asset value, likelihood, existing control coverage and an uncertainty term sits alongside them.

Which controls does the course expect you to be able to compare?

Four firewall generations, distinguished by what each can observe, and three perimeter architectures distinguished by where the filtering sits. Detection systems on two independent axes, network or host placement and signature or anomaly comparison. Access control across identification, authentication, authorisation and accountability, with three models separated by who decides.

Application controls across six subsystems from boundary through to output. In each case the examinable point is the blind spot rather than the capability.

What does the course expect you to know about data protection in Hong Kong?

Six data protection principles, covering collection, accuracy and retention, use, security, openness, and access and correction. The distinction worth carrying into an answer is that only one of the six concerns keeping data safe.

Retention beyond need, use beyond the purpose stated at collection, and refusal of an access or correction request are all breaches while nothing has leaked at all, which is the most common misreading of the regime in student work.

What is the individual assignment asking for, and how is it different from the project?

It asks you to choose three separate aspects of information security from a published list spanning technical, managerial, behavioural, educational and social or legal ground, find one recent item under each, describe it with diagrams and explanation, then say what countermeasure or application follows and what the impact on modern business is. It is a research task about the state of the field.

The project is consultancy on one real organisation, which is a different skill assessed on a different deliverable.

Study strategy

How to study for the exam

Carry one organisation you actually know through every chapter and answer that chapter's question about it before reading the chapter's own answer, because the project and the individual assignment both ask for exactly that move and starting either from a blank page in week eight is the most expensive mistake available here.

Then rehearse the four answer shapes rather than re-reading the sessions: state a boundary in one sentence, place a control and say what it can see from there, run the loss expectancy arithmetic with the working shown, and write a recommendation containing a named control, the risk it reduces and a reason a manager would fund it.

Study IS6523 with AI

Your AI Information Technology tutor for IS6523

Stuck on a hard IS6523 question? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Information Systems Infrastructure and Security Management question and get a clear, step-by-step explanation grounded in how the course is actually taught and assessed. Read this whole study guide free, then take your hardest questions to Sia.

A+Everything unlocked
Unlocks this Bible + all 6 of your City University of Hong Kong subjects - and 1,000+ Bibles across every Australian university.
Sia - your IS6523 tutor, unlimited, worked the way the exam marks it
The full 61-page Bible + practice bank with worked solutions
Chrome extension - sync your LMS so Sia knows your deadlines
Bilingual EN / Chinese on every Bible and every Sia answer
$0.99 Trial
30-day money-back · cancel in one tap · how it works