EM 589 Cybersecurity for Engineering Managers
3 Credit Hours
Every aspect of modern organizations relies on effective technology solutions. Back-office functions, internal communications, development of intellectual property, creation of proprietary content, customer experience, and development and delivery of products and services are all powered by cyber technologies. Organizations that cannot effectively protect these essential cyber technologies will struggle to succeed.
Many view the protection of these technology solutions as purely an IT issue. But smart leaders understand that cybersecurity is not simply an IT problem, it is a business problem. This course will teach students to better understand modern cyber threats and how to effectively analyze and manage them as business risks. Students will learn how effective management of cybersecurity risks can enable smarter business decisions and position them and their organizations for success.
This is not a course that teaches students to be a technical expert in any specific area of cybersecurity. While this course will address some specific cyber attack and protection techniques, it does not focus on teaching the deep technical expertise required to be a technical cybersecurity professional. This course focuses on teaching fundamental cybersecurity concepts, how to apply these concepts in business organizations, and why these concepts are important to organizational success. Students will learn about different frameworks for protecting cyber assets, and how to view cyber protection through the lens of business risk.
Prerequisite
Graduate standing.
Course Objectives
By the end of the course, students will be able to:
- Understand what cybersecurity is (and is not)
- Understand and articulate why cybersecurity is important for all organizations
- Understand why securing cyber assets is challenging for most organizations
- Explain essential cybersecurity protection concepts
- Understand the current cyber threat landscape and how specific controls can be applied to protect against these threats
- Demonstrate familiarity with common frameworks for managing cyber risk including frameworks from NIST, ISO, The Center for Internet Security (CIS) and MITRE
- Apply risk assessment and risk management practices to appropriately defend against common cyber threats
- Leverage a strong cybersecurity program as an enabler of organizational success
Course Topics
The course will address the following cybersecurity topics:
- Cybersecurity Fundamentals
o What is cybersecurity, why is it important, why is it so challenging
o Key terminology and definitions
o Cybersecurity design fundamentals - Common Cybersecurity Frameworks
- Essential practices for good cyber hygiene
- Protections to defend against common cyber threats
- Common techniques and tactics used by threat actors to threaten cyber assets
- Cyber threat identification and proper application of controls to effectively manage cyber risk
- Risk identification and assessment, frameworks for effective management of cybersecurity risk
- Security Policies
- Asset Classification
- Data Protection
- Compliance, Laws, and Regulations Impacting Cybersecurity
- Cybersecurity Incident Management and Incident Response
- Open Source Intelligence (OSINT)
- How AI technologies are impacting the Cyber Threat Landscape
- Humans in Cybersecurity
o Cybersecurity Awareness and Education
o Social Engineering and Attacks on Humans - Disaster Recovery and Business Continuity
- Operational Technology (OT) and Internet-Of-Things (IoT) Cybersecurity Risks and Protections
- Third-Party Risk Management and Supply Chain Cybersecurity Risks
Course Requirements
| Assignment | Percentage | Description |
|---|---|---|
| Homeworks | 25% | Homework assignments will be made in most class sessions and will also be posted in the Moodle site. Generally, assignments will be due before the start of the next class, unless otherwise specified by the instructor. |
| Quizzes | 30% | A quiz will be given at the end of many class sessions. Quizzes will generally be open-note based on topics covered in the course. In some classes, an assignment / exercise will serve as a quiz for that class session. |
| Exams | 20% | The course will have a mid-term and a final exam. |
| Projects | 25% | Three projects will be assigned during the semester. |
Textbooks
Required Textbook
The following textbook is required for this course:
ISC2 CISSP Certified Information Systems Security Professional Official Study Guide (Sybex Study Guide) 10th Edition
Authors: Mike Chapple, James Michael Stewart, Darril Gibson
ISBN-10: 1394254695
ISBN-13: 978-1394254699
Other Reference Materials
This course will utilize reference materials available online from sources such as the National Institute of Standards and Technology (NIST), the Center for Internet Security (CIS), the Cybersecurity & Infrastructure Security Agency (CISA), the MITRE Corporation, and other government and commercial entities. These resources will be provided electronically or via reference to freely available online sources.
Other Reading Materials
Supplemental reading on relevant issues will be required throughout the course. Case studies and other reading materials will be assigned and provided electronically or via reference to freely available online sources.
Created: 08/13/2026.
- Categories: