Skip to content

CS 331: Objective Alignment Sheet ​

Spring 2027 · Computer Security and Information Assurance

This page maps every learning objective in CS 331 to the exact lab or discussion that measures it. The course has no quizzes and no exams. It is the markdown counterpart of the CS 331 Objective Alignment Sheet spreadsheet (sheet Objectives).

Two facts that hold for every objective on this page ​

  1. Introduced in this course. Nothing here is reviewed from, built on, or assumed covered in a previous course. CS 331 is the first security course students take, and it draws students from several departments; every objective is taught from the beginning.
  2. Required. There are no optional objectives. Every objective below is attached to a mandatory, graded assignment.

Because these two columns from the spreadsheet are constant across all 34 supporting objectives, they are stated once here rather than repeated in every row.

How this page maps to the spreadsheet ​

Spreadsheet columnWhere it appears here
A: Obj. #The # column; TLO n in each section heading
B: Objectives: The student will be able to…The section heading (terminal) and the The student will be able to… column (supporting)
C: Introduced / Reviewed / Built OnConstant: Introduced In This Course, stated above
D: Required / Optional / Covered PreviouslyConstant: Required, stated above
E: Bloom LevelThe Bloom column, and the italic line under each terminal objective
F: Knowledge TypeThe Knowledge type column, and the italic line under each terminal objective
G: How it will be assessedThe How it will be assessed column, naming the specific rubric rows
H: Location in courseThe Location in course column, as a week number and a link to the assessment
I: NOTESNotes appear beneath the table for the terminal objectives that need one

Bloom levels use the spreadsheet's controlled vocabulary: Create · Evaluate · Analyze · Apply · Understand · Remember. Knowledge types likewise: Principle · Process · Procedure · Concept · Fact.

A note on links. The Location in course links point to the course pages, and they work both on this site and in Canvas.


TLO 1: Security goals, terminology, principles, ethics, and regulation ​

The student will be able to explain core security goals, terminology, first principles, ethical obligations, and the role of privacy and regulation in security practice.

Introduced in this course · Required · Bloom: Understand · Knowledge type: Concept

#The student will be able to…BloomKnowledge typeHow it will be assessedLocation in course
1.1Define confidentiality, integrity, and availability, and identify which goal a described failure violates.RememberFactLab 0 rubric row 3Week 1: 0.05 Lab 0: Course Setup and CyBOK Navigation
1.2Use the terms threat, vulnerability, attack, and risk correctly in writing about a security incident.UnderstandConceptD1 rubric row 1Week 1: 0.03 D1: Introductions and the Security Mindset
1.3Apply the Saltzer and Schroeder design principles to critique a familiar system.ApplyPrincipleLab 1 rubric rows 2-3Week 2: 2.02 Lab 1: Security Principles Audit
1.4Explain how human error and usability failures contribute to security incidents.UnderstandConceptLab 1 rubric row 3Week 2: 2.02 Lab 1: Security Principles Audit
1.5Describe the legal, regulatory, and ethical constraints on security work, including vulnerability disclosure and privacy obligations.UnderstandPrincipleD2 rubric row 1Week 3: 3.02 D2: Ethics and Privacy Case

Notes. Objectives 1.1-1.2 are carried forward into every later lab and discussion, which assume fluent use of this vocabulary throughout. Reading support: CyBOK §1.1-1.5, §3.1, §3.4-3.5, §3.13, §4.3-4.4, §5.2-5.3.


TLO 2: Modeling subjects, objects, permissions, trust boundaries, and threats ​

The student will be able to model subjects, objects, permissions, trust boundaries, and threats using access control matrices, policy descriptions, and basic threat models.

Introduced in this course · Required · Bloom: Apply · Knowledge type: Process

#The student will be able to…BloomKnowledge typeHow it will be assessedLocation in course
2.1Draw a data flow diagram for a described system and mark its trust boundaries.ApplyProcedureLab 2 rubric row 1Week 4: 4.02 Lab 2: Threat Model a Small System
2.2Enumerate threats against a system using STRIDE and record them in a threat table.ApplyProcedureLab 2 rubric row 2Week 4: 4.02 Lab 2: Threat Model a Small System
2.3Assess the likelihood and impact of identified threats using a stated risk method.ApplyProcessLab 2 rubric row 3Week 4: 4.02 Lab 2: Threat Model a Small System
2.4Construct an access control matrix for a given set of subjects, objects, and permissions.ApplyProcedureLab 3 rubric row 1Week 6: 6.02 Lab 3: Access Control Matrix and Least Privilege
2.5Express an access control policy as an ACL, a capability list, and an RBAC assignment, and state the tradeoffs among them.ApplyConceptLab 3 rubric rows 2-3Week 6: 6.02 Lab 3: Access Control Matrix and Least Privilege

Notes. Objective 2.4 requires students to construct a matrix, which needs a rubric rather than a multiple-choice item. This is why week 6 carries a lab rather than a discussion. Reading support: CyBOK §2.2-2.4, §2.6.1-2.6.2, §2.6.6, §14.1-14.3, §14.6.


TLO 3: Comparing cryptographic mechanisms and their limits ​

The student will be able to compare symmetric encryption, public-key cryptography, hashing, digital signatures, key management, and secure communication protocols, including their assumptions and limitations.

Introduced in this course · Required · Bloom: Understand · Knowledge type: Concept

#The student will be able to…BloomKnowledge typeHow it will be assessedLocation in course
3.1Explain what a block cipher and a mode of operation each provide, and demonstrate why ECB mode leaks structure.UnderstandProcessLab 4 rubric row 2Week 7: 7.02 Lab 4: Symmetric Encryption in Practice
3.2Distinguish confidentiality from integrity and authenticity, and name the primitive that supplies each.UnderstandConceptLab 4 rubric rows 3-4Week 7: 7.02 Lab 4: Symmetric Encryption in Practice
3.3Compare symmetric and public-key cryptography by key distribution, performance, and typical use.UnderstandConceptLab 5 rubric row 4Week 8: 8.02 Lab 5: Hashing and Signatures
3.4Verify a digital signature and explain what a verification failure does and does not prove.ApplyProcedureLab 5 rubric rows 2-3Week 8: 8.02 Lab 5: Hashing and Signatures
3.5Interpret an X.509 certificate chain and identify the trust assumptions and failure modes of public key infrastructure.AnalyzeProcessLab 6 rubric rows 1-4Week 10: 10.02 Lab 6: Certificates and TLS

Notes. Objectives 3.1-3.4 fall before spring break and 3.5 falls after it, with Lab 6. CyBOK's cryptography chapter opens with two heavily mathematical sections (§10.1 Mathematics, §10.2 Cryptographic Security Models) that are not assigned: this course starts at §10.3. Reading support: CyBOK §10.3-10.8, §18.3, §18.5.1.


TLO 4: Analyzing common attacks and justifying countermeasures ​

The student will be able to analyze common attacks and vulnerabilities, including phishing, network attacks, SQL injection, and buffer overflows, and justify appropriate countermeasures.

Introduced in this course · Required · Bloom: Analyze · Knowledge type: Process

#The student will be able to…BloomKnowledge typeHow it will be assessedLocation in course
4.1Explain how common network attacks work at the protocol layer where they operate.UnderstandProcessD4 rubric row 1Week 11: 11.02 D4: Network Security in the News
4.2Recommend network defenses (firewalling, segmentation, and monitoring) for a described network.ApplyPrincipleD4 rubric row 2Week 11: 11.02 D4: Network Security in the News
4.3Classify malware by the CyBOK taxonomy and map an incident's observed behavior, including phishing used for initial access, to MITRE ATT&CK techniques.AnalyzeConceptLab 7 rubric rows 1-3Week 12: 12.02 Lab 7: Malware Triage Without Malware
4.4Trace a buffer overflow in C source to the stack layout that makes it exploitable, and evaluate which mitigations would stop it.AnalyzeProcessLab 8 rubric rows 1-3Week 13: 13.02 Lab 8: Memory Safety and Assurance Evidence
4.5Perform and then remediate a SQL injection, and explain why parameterization defeats it.AnalyzeProcedureLab 9 rubric rows 1-3Week 14: 14.02 Lab 9: SQL Injection

Notes. Phishing is assessed inside objective 4.3 as an initial-access technique, which is how it appears in real incident reporting and in MITRE ATT&CK (T1566). No lab in this course requires running malware, exploiting a live system, or attacking a machine you do not own; Lab 8 analyzes source code and compiler output, and Lab 9 attacks a local SQLite database that ships with the course. Reading support: CyBOK §6.1-6.2, §6.4, §7.2, §15.1.1, §15.2, §15.4, §16.2.6-16.2.8, §16.3.1, §16.4.1, §19.1, §19.3.2-19.3.3, §19.4.


TLO 5: Applying authentication, authorization, and secure design principles ​

The student will be able to apply authentication, authorization, least privilege, separation of privilege, fail-safe defaults, and other secure design principles to a system design.

Introduced in this course · Required · Bloom: Apply · Knowledge type: Principle

#The student will be able to…BloomKnowledge typeHow it will be assessedLocation in course
5.1Select authentication factors appropriate to a stated threat model and justify the choice.ApplyPrincipleD3 rubric row 1Week 5: 5.02 D3: Authentication Policy Critique
5.2Evaluate a real password and multi-factor authentication policy against NIST SP 800-63B-4.EvaluatePrincipleD3 rubric rows 1-2Week 5: 5.02 D3: Authentication Policy Critique
5.3Apply least privilege and separation of privilege to reduce an over-broad permission assignment.ApplyPrincipleLab 3 rubric row 4Week 6: 6.02 Lab 3: Access Control Matrix and Least Privilege
5.4Apply fail-safe defaults and complete mediation when critiquing a system design.ApplyPrincipleLab 1 rubric row 2Week 2: 2.02 Lab 1: Security Principles Audit
5.5Recommend a prevention-first countermeasure (a language, API, or coding practice) for a class of vulnerability.ApplyPrincipleLab 8 rubric row 4; Lab 9 rubric row 4Week 13: 13.02 Lab 8: Memory Safety and Assurance Evidence · Week 14: 14.02 Lab 9: SQL Injection

Notes. This objective is spread deliberately: principles are introduced in week 2 (5.4), applied to authentication in week 5 (5.1, 5.2), to authorization in week 6 (5.3), and to code in weeks 13-14 (5.5). Reading support: CyBOK §1.4, §14.1-14.3, §14.5, §15.2; NIST SP 800-63B-4 §3.


TLO 6: Interpreting assurance arguments and evidence ​

The student will be able to interpret assurance arguments and evidence, and evaluate whether a system's security claims are supported by its design, implementation, and testing.

Introduced in this course · Required · Bloom: Evaluate · Knowledge type: Principle

#The student will be able to…BloomKnowledge typeHow it will be assessedLocation in course
6.1Distinguish prevention, detection, and mitigation of vulnerabilities as distinct classes of assurance evidence.UnderstandConceptLab 8 rubric row 4Week 13: 13.02 Lab 8: Memory Safety and Assurance Evidence
6.2Identify what a static or dynamic analysis result does and does not establish about a program.AnalyzeConceptLab 8 rubric row 4Week 13: 13.02 Lab 8: Memory Safety and Assurance Evidence
6.3Evaluate whether stated security claims about a system are supported by the design and testing evidence offered.EvaluatePrincipleLab 8 rubric row 4Week 13: 13.02 Lab 8: Memory Safety and Assurance Evidence
6.4Describe how a maturity model or evaluation scheme (SAMM, BSIMM, or the Common Criteria) supplies organizational assurance evidence.UnderstandProcessLab 8 rubric row 4Week 13: 13.02 Lab 8: Memory Safety and Assurance Evidence

Notes. This terminal objective has four supporting objectives rather than five. It is the narrowest outcome in the course: assurance is taught in one week (13) through CyBOK §15.2, §15.4, and §17.4, and assessed through Lab 8's closing section (rubric row 4). If assurance needs more weight in a future offering, the natural place to add it is Lab 8's evidence section rather than an additional week: the 8-hour weekly budget has no room for a sixteenth topic.


TLO 7: Analyzing detection data and recommending a response ​

The student will be able to analyze basic intrusion-detection data and recommend a defensible response using an appropriate detection model.

Introduced in this course · Required · Bloom: Analyze · Knowledge type: Process

#The student will be able to…BloomKnowledge typeHow it will be assessedLocation in course
7.1Identify the data sources a detection capability draws on and state what each can and cannot show.UnderstandConceptLab 10 rubric row 1Week 15: 15.04 Lab 10: Log Analysis and Incident Memo
7.2Distinguish misuse detection from anomaly detection and choose one for a stated scenario.EvaluateConceptLab 10 rubric row 4Week 15: 15.04 Lab 10: Log Analysis and Incident Memo
7.3Analyze authentication and web server logs to identify brute-force and scanning activity.AnalyzeProcedureLab 10 rubric rows 2-3Week 15: 15.04 Lab 10: Log Analysis and Incident Memo
7.4Explain the base-rate fallacy and its effect on alert volume in a detection system.UnderstandPrincipleLab 10 rubric row 5Week 15: 15.04 Lab 10: Log Analysis and Incident Memo
7.5Recommend a defensible incident response structured by the NIST SP 800-61 incident response phases.EvaluateProcessLab 10 rubric row 6; D5 rubric row 1Week 15: 15.04 Lab 10: Log Analysis and Incident Memo · Week 15: 15.02 D5: A Current Security Failure

Notes. Objective 7.4 (the base-rate fallacy) is the one piece of quantitative reasoning in the course; it is taught with worked arithmetic on the week 15 lecture notes page so that students without a statistics background can complete it. Reading support: CyBOK §8.1-8.2, §8.3.1-8.3.3, §8.3.6, §8.7; NIST SP 800-61r3.


Reverse index: what each assessment measures ​

The table an assessment reviewer usually wants: one row per graded item, listing the supporting objectives it measures and its point value.

WeekAssessmentPointsObjectives measured
10.05 Lab 0: Course Setup and CyBOK Navigation201.1
10.03 D1: Introductions and the Security Mindset151.2
22.02 Lab 1: Security Principles Audit381.3, 1.4, 5.4
33.02 D2: Ethics and Privacy Case301.5
44.02 Lab 2: Threat Model a Small System382.1, 2.2, 2.3
55.02 D3: Authentication Policy Critique305.1, 5.2
66.02 Lab 3: Access Control Matrix and Least Privilege382.4, 2.5, 5.3
77.02 Lab 4: Symmetric Encryption in Practice383.1, 3.2
88.02 Lab 5: Hashing and Signatures383.3, 3.4
1010.02 Lab 6: Certificates and TLS383.5
1111.02 D4: Network Security in the News304.1, 4.2
1212.02 Lab 7: Malware Triage Without Malware384.3
1313.02 Lab 8: Memory Safety and Assurance Evidence384.4, 5.5, 6.1, 6.2, 6.3, 6.4
1414.02 Lab 9: SQL Injection384.5, 5.5
1515.04 Lab 10: Log Analysis and Incident Memo387.1, 7.2, 7.3, 7.4, 7.5
1515.02 D5: A Current Security Failure307.5
Finals16.01 D6: Final Reflection15Self-assessment against TLO 1-7; no single objective scored
Total550

Coverage check ​

Every one of the 34 supporting objectives is measured by at least one graded rubric row in a lab or discussion. The table below is the count per objective.

TLOSupporting objectiveMeasured byCount
11.1Lab 01
11.2D11
11.3Lab 11
11.4Lab 11
11.5D21
22.1Lab 21
22.2Lab 21
22.3Lab 21
22.4Lab 31
22.5Lab 31
33.1Lab 41
33.2Lab 41
33.3Lab 51
33.4Lab 51
33.5Lab 61
44.1D41
44.2D41
44.3Lab 71
44.4Lab 81
44.5Lab 91
55.1D31
55.2D31
55.3Lab 31
55.4Lab 11
55.5Lab 8, Lab 92
66.1Lab 81
66.2Lab 81
66.3Lab 81
66.4Lab 81
77.1Lab 101
77.2Lab 101
77.3Lab 101
77.4Lab 101
77.5Lab 10, D52

With no quizzes or exams, most objectives are measured once, by the lab or discussion in the week that teaches them. Only 5.5 (Labs 8 and 9) and 7.5 (Lab 10 and D5) are measured twice. A lab rubric row is a performance measure rather than a recognition check, and labs carry the largest point values in the course, but there is no second, later check on what students retained. That is the honest limit of a course with no exams and no multi-week project.

Released under the MIT License.