Overview
This course provides a principled and practical examination of cybersecurity and secure systems. It develops the confidentiality, integrity, availability, authenticity, accountability, and nonrepudiation objectives that inform the protection of computing systems, networks, applications, and data.
Topics include risk management, attack surfaces, trust boundaries, threat modelling, security policies, defence in depth, authentication and authorisation, identity and access management, cryptography, operating-system and network security, secure software development, cloud and emerging-platform security, privacy, and legal and ethical responsibilities.
Students apply security tools in authorised, isolated laboratory environments to identify vulnerabilities, assess risk, recommend mitigations, design secure architectures, and document incident detection, evidence preservation, containment, recovery, and post-incident analysis procedures.
Learning Outcomes
- Analyse security objectives, attack surfaces, trust boundaries, threats, vulnerabilities, and risks in computing environments.
- Evaluate authentication, authorisation, identity management, password, multifactor, and least-privilege controls.
- Explain and apply symmetric and public-key cryptography, hashing, digital signatures, certificates, key management, and secure protocols.
- Identify vulnerabilities involving injection, broken access control, memory errors, cross-site scripting, insecure deserialization, and software supply chains in controlled environments.
- Assess operating-system, network, endpoint, cloud, mobile, Internet of Things, and container security controls.
- Design secure architectures using segmentation, firewalls, intrusion detection and prevention, secure configuration, defence in depth, and appropriate monitoring.
- Develop secure software lifecycle practices incorporating code review, security testing, logging, vulnerability management, and remediation planning.
- Formulate incident-response procedures covering detection, evidence preservation, containment, eradication, recovery, communication, and post-incident analysis.
- Defend security recommendations with reference to privacy, legal obligations, professional ethics, and organisational risk.
Timetable
| Type | Length | Frequency | Period |
|---|---|---|---|
| Lecture | 2 hours | Weekly | All semester |
| Lab | 2 hours | Weekly | All semester |
| Tutorial | 1 hour | Fortnightly | All semester |
| Workshop | 2 hours | Fortnightly | Second term |
Assessment Schedule
| Type | Description | Weighting |
|---|---|---|
| Assignment | Laboratory exercises (10 × 2%) | 20.00% |
| Assignment | Threat modelling and risk assessment | 15.00% |
| Assignment | Secure architecture design | 15.00% |
| Test | Controlled vulnerability assessment | 15.00% |
| Capstone | Incident-response capstone | 25.00% |
| Exam | Final examination | 10.00% |
Prerequisites
Teaching Staff & Programs
This course is delivered jointly by faculty from the participating programs listed below. In line with the Douchewater Way, the University of Sexology tailors core instruction directly to each cohort's specific discipline — adapting curriculum to program needs rather than forcing students into a one-size-fits-all model. Learn more about our approach at The Douchewater Way.

