Hogeschool West-Vlaanderen
Howest Brugge
Spoorwegstraat 4 - 8200 Brugge
Tel: 050 682666
studentadmin@howest.be - Website: www.howest.be
Risk Management, Threat Modelling and Security Policy20554/2013/2627/1/06
Study guide

Risk Management, Threat Modelling and Security Policy

20554/2013/2627/1/06
Academic year 2026-27
Is found in:
  • Bachelor of Cybersecurity, programme stage 4
This is a single course unit.
Study load: 3 credits
Total study time: 75,00 hours
Re-sit exam: is possible.
It is not possible to enrol in this course unit under
  • exam contract (to obtain a credit).
  • exam contract (to obtain a degree).
Co-ordinator: Galle Johan
Other teaching staff: Klykens Johan, Verbeke Koen
Language course: No
Languages: English

Omschrijving Volgtijdelijkheid (VT) (EN)

previously registered for Cyber Security Essentials AND (previously registered for Data Privacy and IT Law OR previously registered for Data Privacy and IT Law).

Omschrijving Doelstellingen (EN)

LR01:

01.1.1 Defines methods for cybersecurity risk analysis and treatment

01.1.2 Explains principles of cybersecurity and the principles of relevant standards and frameworks related to cybersecurity

01.1.3 Enumerates possible organizational and high- level technical measures for mitigating risks and threats

01.2.1 Enumerates possible organizational and high- level technical measures for mitigating risks and threats

01.3.1 Selects appropriate measures to mitigate risks

01.3.2 Selects appropriate measures to mitigate risks

01.3.3 Evaluates measures that reduce the impact or likelihood of identified threats or risks in a realistic simulated context

LR04:

04.1.1 Describes for each phase of cyber security the possible security measures and their context

04.1.2 Defines identification, authentication, authorization

04.1.3 Articulates and characterizes the different environments such as IT, OT, IOT, within which cyber security is applied, including physical security of cyber assets

04.2.2 Secures applications in an IT, OT, IOT, cloud, container, and physical context

04.3.1 Secures applications in an IT, OT, IOT, cloud, container, and physical context

LR06:

06.1.1 Defines the principles of usable cybersecurity including all factors that affect it

06.1.2 Defines the principles of usable cybersecurity including all factors that affect it

06.1.3 Recognizes and frames cybersecurity requirements

06.2.1 Applies awareness principles

06.2.2 Assesses cybersecurity requirements

06.3.2 Establishes policies relevant to cybersecurity including awareness

06.3.3 Identifies and analyzes cybersecurity needs and change processes in a simulated realistic context

LR08:

08.2.1 Identifies and analyzes cybersecurity needs and change processes in a simulated realistic context

08.2.2 Communicates and reports in writing and orally in a professional manner in English, using the correct professional jargon

08.2.3 Communicates and reports in writing and orally, avoiding language errors

08.2.4 Uses the appropriate tools in communication and reporting

08.3.1 Communicates and reports in writing and orally in a structured and unambiguous manner tailored to the interlocutor, pays attention to the avoidance of language errors and the correct use of jargon

LR09:


09.1.3 Describes the appropriate legal, deontological and ethical frameworks around offensive and defensive cybersecurity, including cybercrime and cyberwarfare

09.2.2 Applies data protection legislation

09.2.3 Applies legal, deontological and ethical principles

09.3.1 Conducts an impact assessment of a project or threat and which takes into account the relevant regulations

LR10:

10.1.2 Describes the concepts of a cybersecurity improvement project and maturity models

10.1.5 Describes the rules for giving feedback receive and ask for feedback

10.2.1 Executes a simple cybersecurity project within the preconditions

10.2.3 Adapts his/her behavior in relation to an optimal collaboration and acts upon team goals

LR11:

11.2.2 Describes the principles, importance and goals of professional development and lifelong learning

11.3.1 Translates non-cyber events into possible cyber consequences

11.3.2 Critically assesses the relevance of cybersecurity sources

11.3.3 Actively follows (inter)national developments within cybersecurity

Omschrijving Inhoud (EN)

1. Security governance

Risk management
Information Security Management System (ISMS)
Information security controls
Privacy & security by design

2. Security legislation

Cybersecurity on products
Cybersecurity on organisations
Vulnerability management

3. Threat management

Threat modelling

Omschrijving Studiematerialen (lijst) (EN)

CasesMandatory
PresentationMandatory
TutorialsMandatory

Omschrijving Eindcompetenties (lijst) (EN)

PBACS001: Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
CodeDescription
PBACS001Analyses critical business processes, data and infrastructure and makes a substantial contribution to cybersecurity by design and data protection by design through the identification, evaluation and mitigation of risks and threats, establishing an information security policy, including strategic objectives, procedures, guidelines and policies.
PBACS002: Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
CodeDescription
PBACS002Collects, analyses, structures and shares actionable threat intelligence information that includes the behaviour, motives and capability of cybercriminals, including phishing and ransomware.
PBACS004: Selects and configures the optimal techniques, including identification, authentication and authorization and applies these within mainstream environments including physical and industrial environments for each phase of the cyber security process.
CodeDescription
PBACS004Selects and configures the optimal techniques, including identification, authentication and authorization and applies these within mainstream environments including physical and industrial environments for each phase of the cyber security process.
PBACS006: Strengthens cyber security awareness, supports necessary change processes, and provides organisation-specific advice on data and business process security architecture and maintenance.
CodeDescription
PBACS006Strengthens cyber security awareness, supports necessary change processes, and provides organisation-specific advice on data and business process security architecture and maintenance.
PBACS008: Communicates, reports and consults,at least in Dutch and English, on cyber security incidents and action plans with various stakeholders in a professional manner adapted to the target audience.
CodeDescription
PBACS008Communicates, reports and consults,at least in Dutch and English, on cyber security incidents and action plans with various stakeholders in a professional manner adapted to the target audience.
PBACS009: Acts with ethical responsibility in the areas of cybersecurity, intelligence, data protection, cyber crime, forensic investigation and cyber warfare taking into account the legal and deontological framework and the impact on individuals, organizations and society.
CodeDescription
PBACS009Acts with ethical responsibility in the areas of cybersecurity, intelligence, data protection, cyber crime, forensic investigation and cyber warfare taking into account the legal and deontological framework and the impact on individuals, organizations and society.
PBACS010: Initiates, implements, substantiates, documents cybersecurity projects tailored to the organisation, working in a team-oriented way in a multidisciplinary context, setting appropriate priorities and demonstrating good time management, problem-solving ability. and self-critical attitude.
CodeDescription
PBACS010Initiates, implements, substantiates, documents cybersecurity projects tailored to the organisation, working in a team-oriented way in a multidisciplinary context, setting appropriate priorities and demonstrating good time management, problem-solving ability. and self-critical attitude.
PBACS011: Directs its own professional development based on monitoring and consultation of relevant sources and practice-oriented research into (inter)national developments in cyber security and the domains that influence it with a view to lifelong learning.
CodeDescription
PBACS011Directs its own professional development based on monitoring and consultation of relevant sources and practice-oriented research into (inter)national developments in cyber security and the domains that influence it with a view to lifelong learning.

Omschrijving Onderwijsvorm (EN)

  • Lecture
  • Project

Omschrijving Evaluatie (lijst) (EN)

Evaluation(s) for first exam chance
MomentForm%Remark
exam period 2 (2nd sem) (regular exam schedule)exam: written50,00
Evaluation(s) for re-sit exam
MomentForm%Remark
exam period 2 (2nd sem) (regular exam schedule)exam: written50,00
Evaluation(s) for both exam chances, not reproducible in re-sit exam
MomentForm%Remark
exam period 2 (outside exam schedule)assignment: written50,00