CS 331: Computer Security and Information Assurance
Catalog Description
Fundamentals of computer security and information assurance. Topics include security goals, access control, common software and network vulnerabilities, cryptography, security policies and procedures.
Course Logistics
- Email: shanepanter (at) boisestate.edu
- Office Hours: Appointments are available by request
- Classroom: Online (Asynchronous)
- Semester: Spring 2027
- Class Time: N/A (Asynchronous)
- Prerequisites: Complete at least one of the following: CS 117, CS 121, ITM 225
Who This Course Is For
This is the first security course most students take, and it is open across departments: computer science, information technology management, and others. The only assumption is that you have completed one introductory programming course.
You will not be asked to write a program from scratch. Every lab that involves code gives you a working, commented Python script, and your job is to run it, change a value or two, read the output, and explain what happened and why. There is no virtual machine to install, no Linux server to configure, and no version control to learn. If you can open a terminal and a web browser, you have everything you need.
Course Materials
No textbook purchase is required. The required text is:
The Cyber Security Body of Knowledge, version 1.1.0. Awais Rashid, Howard Chivers, Emil Lupu, Andrew Martin, and Steve Schneider (eds.), July 2021. © Crown Copyright, The National Cyber Security Centre 2021, licensed under the Open Government Licence v3.0: http://www.nationalarchives.gov.uk/doc/open-government-licence/
CyBOK is a free, openly licensed reference written by the people who work in each area. The complete PDF is in this course at docs/CyBOK_v1.1.0.pdf and in Canvas Files. You never have to go anywhere else to get a reading.
Two things to know about it:
- We use about a third of the book, deliberately. CyBOK covers 21 knowledge areas including several (formal methods, hardware security, cyber-physical systems) that belong in later courses. The weeks below name the exact sections you are responsible for. You are not expected to read anything else.
- CyBOK is a reference, not a tutorial. It is precise and compact rather than chatty. Each week's lecture notes page adds a worked example that shows the idea applied once, concretely, plus a plain-language supplement where one helps.
Finding a reading: CyBOK section numbers (for example, §10.4) are the reliable way to navigate. Every page of the PDF prints its page number in the footer, which may not match your PDF viewer's page counter, because the book has 38 pages of front matter. Use your viewer's search box or the bookmarks panel and go by section number.
A complete list of readings, supplements, and their licenses is in Readings and Resources.
Required Tools
Everything below is free. You can use any operating system your laptop supports. Linux is the ground truth: if a command or its output is different on your machine, the Linux behavior is the one the course and the grading go by.
| Tool | Why | Notes |
|---|---|---|
| A web browser | Readings, Canvas, and Labs 0, 6, 7, and 8 | Any modern browser |
| Python 3.11 or newer | Labs 4, 5, 6, and 9 and the week 5 discussion run a provided script | Free from https://www.python.org/downloads/, and Lab 0 checks your version |
The cryptography package | Labs 4, 5, and 6 only | One pip install cryptography, walked through step by step in Lab 0 |
You do not need a virtual machine, a Linux server, Docker, git, or a GitHub account. If your own machine gives you trouble, every lab runs on the lab machines described under IT Support Policy.
Course Workflow
Every week follows the same rhythm, and nothing in this course spans more than one week:
- Read the assigned CyBOK sections (about 15 pages of close reading, plus the occasional skim) and the week's supplement.
- Work through the module in Canvas. Its Overview page lists the objectives and what is due when; its Readings and Lecture Notes page includes a worked example.
- Complete one graded activity: either a lab or a discussion, never both in the same week.
There is no semester-long project and no assignment that carries over from one week to the next. If you fall behind, you can catch up in a single week.
Everything is submitted in Canvas. Labs are a single text entry or one attached file. Discussions happen in the Canvas discussion boards. There are no quizzes and no exams.
Weekly Time Budget
This course is designed to take 8 hours per week or less, including everything: reading, lecture notes, labs, discussions, and study time. A typical week:
| Activity | Time |
|---|---|
| CyBOK reading (about 15 pages) and note-taking | 1.5-2.0 hrs |
| Lecture notes and worked example | 0.5-1.0 hrs |
| One lab (weeks with a lab) | 1.5-2.0 hrs |
| or one discussion: initial post and replies (weeks with a discussion) | 1.0 hrs |
| Review, questions, and slack | 2.0-2.5 hrs |
| Typical total | 5.5-7.5 hrs |
Every lab is scoped to be finished in one sitting of about 90 minutes. If a lab is taking you much longer than that, stop and email me: that is a problem with the lab, not with you.
Learning Outcomes
This course has seven terminal learning objectives. Every objective is introduced in this course, and every objective is required: there are no optional objectives and nothing here assumes you covered it somewhere else.
Each terminal objective breaks down into supporting objectives that name the exact lab or discussion that measures them. The complete alignment is on the Objective Alignment Sheet.
| # | The student will be able to… | Bloom level |
|---|---|---|
| TLO 1 | Explain core security goals, terminology, first principles, ethical obligations, and the role of privacy and regulation in security practice. | Understand |
| TLO 2 | Model subjects, objects, permissions, trust boundaries, and threats using access control matrices, policy descriptions, and basic threat models. | Apply |
| TLO 3 | Compare symmetric encryption, public-key cryptography, hashing, digital signatures, key management, and secure communication protocols, including their assumptions and limitations. | Understand |
| TLO 4 | Analyze common attacks and vulnerabilities, including phishing, network attacks, SQL injection, and buffer overflows, and justify appropriate countermeasures. | Analyze |
| TLO 5 | Apply authentication, authorization, least privilege, separation of privilege, fail-safe defaults, and other secure design principles to a system design. | Apply |
| TLO 6 | Interpret assurance arguments and evidence, and evaluate whether a system's security claims are supported by its design, implementation, and testing. | Evaluate |
| TLO 7 | Analyze basic intrusion-detection data and recommend a defensible response using an appropriate detection model. | Analyze |
Schedule
The schedule may be adjusted due to factors such as instructor availability, student progress, and current events. Weeks run Monday through Sunday. Because the course is asynchronous, dates are release and due anchors rather than meeting times. Exact due dates are posted in Canvas.
All readings marked § refer to CyBOK v1.1.0; page numbers are the printed page numbers shown in the PDF's footers.
| Week | Dates | Topic | Reading | Graded this week |
|---|---|---|---|---|
| 1 | Jan 11-17 | What is cyber security? Goals, terms, and failures | §1.1-1.3 (pp. 2-8) | Lab 0; D1 |
| 2 | Jan 18-24 | Security principles and the human factor | §1.4-1.5 (pp. 9-15); §4.3-4.4 (pp. 158-165) | Lab 1 |
| 3 | Jan 25-31 | Law, regulation, ethics, and privacy | §3.1 (pp. 52-58); §3.4-3.5, skim (pp. 72-86); §3.13 (pp. 122-127); §5.2-5.3 (pp. 187-191) | D2 |
| 4 | Feb 1-7 | Risk management and threat modeling | §2.2-2.4 (pp. 20-26); §2.6.1-2.6.2 (pp. 31-33); §2.6.6 (pp. 43-45) | Lab 2 |
| 5 | Feb 8-14 | Authentication and credentials | §14.5 (pp. 479-489) | D3 |
| 6 | Feb 15-21 | Authorization, access control, and accountability | §14.1-14.3 (pp. 466-475); §14.6 (pp. 489-493) | Lab 3 |
| 7 | Feb 22-28 | Symmetric cryptography | §10.3-10.5 (pp. 329-338) | Lab 4 |
| 8 | Mar 1-7 | Public-key cryptography, hashing, and signatures | §10.6-10.8 (pp. 338-347) | Lab 5 |
| 9 | Mar 8-14 | Review and catch-up | No new reading | Nothing due |
| Mar 15-19 | SPRING BREAK: no class meetings, nothing due | |||
| 10 | Mar 22-28 | Keys, certificates, PKI, and TLS | §18.3 (pp. 625-635); §18.5.1 (pp. 639-640) | Lab 6 |
| 11 | Mar 29-Apr 4 | Network security and attacks | §19.1 (pp. 646-648); §19.3.2-19.3.3 (pp. 656-665); §19.4 (pp. 671-677) | D4 |
| 12 | Apr 5-11 | Malware and adversarial behaviors | §6.1-6.2 (pp. 202-207); §6.4 (pp. 214-219); §7.2 (pp. 236-242) | Lab 7 |
| 13 | Apr 12-18 | Software security, memory safety, and assurance | §15.1.1 (pp. 500-501); §15.2 (pp. 507-512); §15.4 (pp. 516-520); §17.4 (pp. 582-585) | Lab 8 |
| 14 | Apr 19-25 | Web security and injection | §16.2.6-16.2.8 (pp. 536-540); §16.3.1 (pp. 543-545); §16.4.1 (pp. 547-552) | Lab 9 |
| 15 | Apr 26-30 | Security operations, detection, and incident response | §8.1 (pp. 253-256); §8.2, skim (pp. 256-263); §8.3.1-8.3.3 (pp. 264-268); §8.3.6 (p. 270); §8.7 (pp. 283-286) | Lab 10; D5 |
| Finals | May 3-7 | Wrap-up | No new reading | D6 reflection |
Spring break, the last day of instruction (April 30), and finals week (May 3-7) follow the registrar's academic calendar.
Assessments
The course is worth 550 points, and your grade is the points you earn out of 550. There are no quizzes and no exams. Every graded item is completed within a single week.
| Assessment | Points | Share | Description |
|---|---|---|---|
| Labs | 400 | 73% | Eleven single-sitting labs: Lab 0 (20 pts) plus Labs 1-10 (38 pts each) |
| Discussions and reflections | 150 | 27% | Six Canvas discussions: D1 (15 pts), D2-D5 (30 pts each), D6 reflection (15 pts) |
| Total | 550 | 100% |
Labs and discussions assess different objectives, so a missed discussion cannot be replaced by extra lab work. Exact point values and due dates are posted in Canvas. Which objective each item measures is listed in the Objective Alignment Sheet.
Grading Policy
Grades will be posted in Canvas, and your final percentage maps to a letter grade using the table below. Final grades will not be rounded. Extra Credit opportunities are available throughout the semester to help improve your final grade.
| Letter Grade | Percentage |
|---|---|
| A | 94% - 100% |
| A- | 90% - 93.99% |
| B+ | 87% - 89.99% |
| B | 84% - 86.99% |
| B- | 80% - 83.99% |
| C+ | 77% - 79.99% |
| C | 74% - 76.99% |
| C- | 70% - 73.99% |
| D+ | 67% - 69.99% |
| D | 64% - 66.99% |
| D- | 60% - 63.99% |
| F | Below 60% |
Extra Credit Opportunities
Standing extra credit is always available to help students on a grading boundary. Extra credit earned over the semester cannot exceed 2.5% of total points offered. This course offers 550 points, so the extra credit maximum is 13.75 points.
Homework Policy
Unless explicitly stated otherwise, all work is individual. Group assignments will be clearly marked. The Kount Learning Center (CCP 241) is accessible 24/7 by proxy card to all students enrolled in CS courses and has all the software you will need.
AI Policy
There is no restriction on AI use in this course. You may use AI tools to help you with your work, but you are responsible for ensuring that your work is accurate and meets the requirements of the assignment. You are strongly encouraged to explore the use of AI tools as part of your learning process, but you should not rely on them exclusively. If you use AI tools, you should disclose this in your work and provide a brief explanation of how you used them.
Attendance Policy
This course is asynchronous. I follow the official attendance policy as defined by the university. Students are responsible for completing the weekly materials and assessments by the posted deadlines. Students who need an approved accommodation or make-up arrangement should contact me as soon as possible.
Late Work Policy
Homework assignments may be submitted up to 2 days late with no penalty. After the grace period, no submissions will be accepted unless prior arrangements were made before the original due date. No work or extra credit will be accepted after the last day of course instruction, except the D6 final reflection, which is due the last day of finals week. The semester must end at some point, so plan accordingly. Work submitted 1 second late is treated the same as work submitted 1 day late. You can find the last day of course instruction on the registrar's academic calendar.
Class Interaction Policy
Class interaction assignments must be completed within the time frame specified in Canvas. Discussion and peer-review activities are most useful when completed during the assigned week, so late participation may receive reduced or no credit when it would disadvantage classmates who participated on time.
This applies to (but is not limited to):
- Discussion posts
- Reflections (written and video)
- Group meetings (virtual or in person)
- Status updates
- Asynchronous activities
Communication Policy
Outside the classroom, communication will be through email, Canvas, and office hours. If you do not receive a reply within 48 hours, verify you are emailing from BroncoMail and send a follow-up. You can also message through Canvas if email is not going through. Please include the following in all emails:
- First and last name
- Student ID
- Course and section number (e.g., CS123-01)
BroncoMail is the official university communication channel. Check it two to three times per week. Your instructor will not respond to emails from personal accounts (Gmail, Yahoo, etc.). See University Policy 2280 for details.
Emails are answered within 24 hours, Monday-Friday, 9:00 am-5:00 pm Mountain Time. Emails sent on weekends or outside those hours will receive a reply on the next business day. Reserve email for private matters such as grades. General course questions belong in the class discussion forum.
IT Support Policy
Your instructor and teaching assistant cannot provide IT support for personal machines. If you cannot get your personal machine configured correctly, use a lab machine to complete your work.
Labs and Other Building Spaces
The CCP building (downtown Boise) has three labs secured by proxy card access. All lab machines are supported by department IT staff and are guaranteed to work.
- Kount Learning Center (CCP 241): Accessible 24/7 by proxy card to all CS students. See the Success & Tutoring page for details.
- CS 121 Classroom Lab (CCP 242): Accessible 24/7 by proxy card, but not available during scheduled courses and labs (see the schedule posted outside the lab).
- Metageek Lab (CCP 240): Accessible 24/7 by proxy card, but not available during scheduled CS courses and labs (see the schedule posted outside the lab).
University Policies
Violations of university policies may result in a failing grade (F) for the course. All students are required to review the following:
Student Support
Boise State cares about your success. Help is available for technical, academic, financial, and personal needs, as well as learning accommodations. Nearly all services are available to online students as well.
- Educational Access Center
- Support Resources
- Academic Support Services
- Accessing University Support Services (full resource guide)