IS6523 Information Systems Infrastructure and Security Management
IS6523 Overview
- City University of Hong Kong
- Semester A, 2026/27
- Department of Information Systems
- Postgraduate, three credit units
- Two hour written examination
What this course is actually asking you to do
The published aim is to examine the key infrastructural and security issues involved in electronic commerce transactions, with a managerial perspective adopted throughout, covering both the electronic payment infrastructure and the transactional security infrastructure.
- Assessed by A two hour written examination worth half the mark, a group security or audit analysis project, an individual research report and class activity.
- The pass condition The catalogue publishes a minimum of 25 per cent in continuous assessment and 25 per cent in the examination, and the teaching plan states both have to be passed.
- The skill being tested Choosing a control for a described business situation and defending the choice on what it costs against what it saves.
- Hardest step The project's risk and countermeasure section carries the largest block of its marks, and groups routinely spend that time on the company profile instead.
- Where to confirm Weights, deadlines and submission settings are controlled by the course site on Canvas.
How IS6523 is assessed
| Component | Weight | Format |
|---|---|---|
| Class Activity | 5% | Class exercises and group discussion across the taught sessions, assessing understanding of the topics and the ability to apply it |
| Individual Assignment | 15% | A written report on new developments related to an existing topic, with critical analysis and the impact on business organisations |
| Project | 30% | A group of about four to six students produces a security or audit analysis report with findings and recommendations, plus a twenty minute presentation |
| Final Examination | 50% | One written examination of two hours, assessing competence in the taught subjects |
The course syllabus lists these four tasks and they total one hundred per cent, split as fifty per cent continuous assessment and fifty per cent examination. Two further points matter. The University catalogue entry publishes a minimum continuous assessment passing requirement of twenty five per cent and a minimum examination passing requirement of twenty five per cent, and the course teaching plan states that both the coursework and the examination have to be passed to pass the course overall; those are two conditions rather than one aggregate. The catalogue also calls its own assessment figures indicative and directs readers to the detailed course information. The teaching materials available here are from an earlier offering, so confirm the split of the class activity mark, and every date, on the current Canvas course site.
Assessment structure
Both halves carry a published minimum passing requirement of 25 per cent, and the course teaching plan states that the coursework and the examination each have to be passed.
What IS6523 covers
Ten chapters follow the taught session sequence from the definition of information security through attack methods, cryptography, payment infrastructure, firewalls, intrusion detection, risk economics, law and governance, auditing and continuity planning.
Information Security, the CIA Triad and the Security Gap
the definition the course opens with · confidentiality, integrity and availability as three kinds of loss · security management as a gap between practice and policy · the four business functions security performs02Attack Methods and the Threat Landscape
threat, vulnerability, attack and threat agent kept apart · the named attack families and what each exploits · denial of service and the handshake it abuses · the threat categories with no attacker behind them03Encryption, Keys and Digital Signatures
substitution, transposition and exclusive-or · symmetric against asymmetric keys · the hybrid envelope · hashes, digital signatures and non-repudiation · public key infrastructure and certificate authorities04Distributed Ledgers and Electronic Payment Systems
blocks, hash pointers and identical copies on every node · transparency and incorruptibility as properties with costs · the four criteria a payment system is judged on · the instruments and the certificate authorities behind them05Access Control, Firewalls and Perimeter Architecture
identification, authentication, authorisation and accountability · mandatory, nondiscretionary and discretionary models · four firewall generations and what each can observe · bastion, screened host and screened subnet · virtual private networks and wireless footprint06Intrusion Detection, Scanning and Biometric Controls
network against host placement · signature against anomaly and the clipping level · port ranges, footprinting and fingerprinting · the lawful conditions on a packet sniffer · Type I and Type II error and the crossover rate07Managing IT Risk and the Economics of Controls
knowing the asset and knowing the threat · identification, analysis, evaluation and treatment · likelihood, uncertainty and the relative risk formula · five treatment strategies · loss expectancy and the cost benefit comparison08Law, Ethics and IT Governance in Information Security
law, policy and ethics and the sanction attached to each · international agreements and their enforceability · the six data protection principles · governance as a board responsibility · a control framework beside a reporting statute09Auditing Systems, Management and Application Controls
collecting and evaluating evidence for an independent opinion · internal, external and independent audits · management controls as layers around application controls · boundary, input, communications, processing, database and output · check digits and the errors they miss10Security Planning, Continuity and Implementation
policy, standard and practice · governance outcomes and the improvement cycle · incident, disaster and continuity plans · hot, warm and cold sites · conversion strategies and change as a controlThat managerial clause is the whole shape of the course. Eleven taught sessions run from a definition of information security to project management for a security programme, and almost none of the assessment rewards being able to describe a technology.
What it rewards is taking a business situation, naming what is at risk in it, naming the mechanism that would attack it, and choosing a control you can defend on cost.
How the sessions build on each other
The first four sessions fix the vocabulary that everything else borrows: the confidentiality, integrity and availability characteristics; the difference between a threat, a vulnerability and an attack; symmetric and asymmetric keys; and what a hash proves.
The middle sessions catalogue the controls, with firewalls and perimeter architecture in one and intrusion detection, scanning tools and biometrics in the next, each instrument presented with a stated reach and a stated blind spot.
The later sessions turn managerial: risk quantified in money, law and governance as constraints, information systems auditing as the production of evidence, and the planning cycle that turns a decision into a programme.
The learning outcomes tell you where the weight sits
The syllabus assigns weightings to its five intended learning outcomes, and the largest share goes to applying security management principles and the legal issues in electronic commerce to the design of security policies and operations.
Applying technical concepts and risk management, evaluating audit principles and control frameworks, and evaluating the security of payment infrastructure each carry a fifth, and communicating security solutions to stakeholders carries the remainder. Three of the five are management outcomes, which is the clearest published signal about how to prepare.
Decide whether a control is worth buying
- 2Compute the single loss expectancy from asset value and exposure factor.
- 3Compute the annualised loss expectancy before and after the control.
- 2Run the cost benefit comparison and state the recommendation.
- 1Name the input the conclusion is most sensitive to.
Key terms
- Information Security
- A considered confidence that an organisation's information exposures and the controls are in balance. The definition is a balance rather than a state of safety, which is why every later topic is a way of making one side of it measurable.
- Security Gap
- The distance between what an organisation currently does and the standard its policies and standards set. Narrowing it with security tools and countermeasures is what the course means by security management.
- Threat
- An object, person or other entity standing as a permanent danger to an asset. It exists whether or not anyone acts, which is what separates it from an attack.
- Vulnerability
- An identified weakness in a controlled system that an attack exploits. Risk identification produces one list of these per information asset.
- Non-repudiation
- The property that stops a party denying, afterwards, that it took part in a transaction. It is produced by encrypting a message digest with a private key, and the course calls it the foundation of digital signatures.
- Demilitarised Zone
- A network segment in which it is the firewall, rather than an internal server, that stands exposed to the outside, with further filtering between it and internal systems.
- Clipping Level
- The boundary of the baseline parameters in an anomaly based detection system. Activity falling outside it triggers a notification to the administrator.
- Crossover Error Rate
- The threshold at which a biometric system's false reject rate equals its false accept rate. It is the single figure that allows two such systems to be compared.
- Annualised Loss Expectancy
- The single loss expectancy multiplied by the annualised rate of occurrence, giving the expected yearly loss from one threat against one asset. It is the benefit term in a cost benefit comparison.
- Residual Risk
- What remains after safeguards have been implemented. The course's stated aim is not an exposure of zero but one matched to the organisation's stated appetite.
- Statement of Applicability
- The planning document recording which control objectives and controls were selected. It is the durable evidence that an omitted control was a decision rather than an oversight.
IS6523 FAQ
How is the mark divided, and does the course have a final examination?
It does. The syllabus divides the mark into four tasks: class activity worth five per cent, an individual assignment worth fifteen, a group project worth thirty, and a final examination worth fifty. That makes the split fifty per cent continuous assessment and fifty per cent examination, and the examination is described as one written paper of two hours assessing competence in the taught subjects.
The catalogue describes its own figures as indicative and points readers to the detailed course information, so confirm the current split on the Canvas course site.
Can a strong project carry a weak examination result?
Not according to the published pass conditions. The University catalogue entry publishes a minimum continuous assessment passing requirement of twenty five per cent and a separate minimum examination passing requirement of twenty five per cent, and the course teaching plan states that both the coursework and the examination have to be passed in order to pass the course overall.
Those are two conditions rather than one total, so coursework and paper each have to clear their own floor before the aggregate matters at all.
What does a two hour written paper actually ask for in a subject this broad?
The course publishes no paper structure, only that the examination is written and runs two hours. What a paper of that length can ask over eleven sessions falls into four shapes: distinguish two terms students collapse, diagnose which control would have caught a described failure, compute a loss expectancy or a cost benefit comparison, and recommend a control for a business situation.
The last of these carries the managerial weight the syllabus says the course adopts throughout, and it needs a named control, the risk it reduces and a funding reason.
Where do the marks concentrate inside the group project?
The project brief publishes its own internal allocation and it is lopsided. Identifying the security risks in each business case and proposing countermeasures carries the largest block, with the business cases themselves close behind and the technical description of the artificial intelligence tools a distant third. The company background and situational analysis carry the smallest block of all.
Groups routinely invert this, which is the most avoidable way to lose marks on a task worth thirty per cent of the course.
How much mathematics does this course contain?
Very little, and all of it is worth knowing exactly because it is the most reliably examinable material in the syllabus. Single loss expectancy is asset value times exposure factor; annualised loss expectancy is that figure times the annualised rate of occurrence; and the cost benefit comparison is the annualised loss expectancy before a control, minus the figure after it, minus the annualised cost of the safeguard.
A relative risk formula combining asset value, likelihood, existing control coverage and an uncertainty term sits alongside them.
Which controls does the course expect you to be able to compare?
Four firewall generations, distinguished by what each can observe, and three perimeter architectures distinguished by where the filtering sits. Detection systems on two independent axes, network or host placement and signature or anomaly comparison. Access control across identification, authentication, authorisation and accountability, with three models separated by who decides.
Application controls across six subsystems from boundary through to output. In each case the examinable point is the blind spot rather than the capability.
What does the course expect you to know about data protection in Hong Kong?
Six data protection principles, covering collection, accuracy and retention, use, security, openness, and access and correction. The distinction worth carrying into an answer is that only one of the six concerns keeping data safe.
Retention beyond need, use beyond the purpose stated at collection, and refusal of an access or correction request are all breaches while nothing has leaked at all, which is the most common misreading of the regime in student work.
What is the individual assignment asking for, and how is it different from the project?
It asks you to choose three separate aspects of information security from a published list spanning technical, managerial, behavioural, educational and social or legal ground, find one recent item under each, describe it with diagrams and explanation, then say what countermeasure or application follows and what the impact on modern business is. It is a research task about the state of the field.
The project is consultancy on one real organisation, which is a different skill assessed on a different deliverable.
How to study for the exam
Carry one organisation you actually know through every chapter and answer that chapter's question about it before reading the chapter's own answer, because the project and the individual assignment both ask for exactly that move and starting either from a blank page in week eight is the most expensive mistake available here.
Then rehearse the four answer shapes rather than re-reading the sessions: state a boundary in one sentence, place a control and say what it can see from there, run the loss expectancy arithmetic with the working shown, and write a recommendation containing a named control, the risk it reduces and a reason a manager would fund it.
Your AI Information Technology tutor for IS6523
Stuck on a hard IS6523 question? Sia is AskSia’s AI Information Technology tutor — ask any IS6523 Information Systems Infrastructure and Security Management question and get a clear, step-by-step explanation grounded in how the course is actually taught and assessed. Read this whole study guide free, then take your hardest questions to Sia.