Data Security and Information Assurance
Currently catalogued as Cybersecurity
Enterprise defense now has to cover systems that are themselves built and operated by AI: prompt injection, tool and model supply-chain compromise, over-scoped agent credentials, and machine-generated code and runbooks reaching production are ordinary incident causes, while detection authoring, log correlation, and triage are increasingly AI-assisted. The course therefore treats the model, retrieval, and agent-tool layer as a first-class attack surface and holds students accountable for evaluating and bounding machine-produced security work.
Current description → proposed description
This course is a survey and overview of methods available to safeguard the information technology used in an enterprise today. IT systems are increasingly under attack and therefore knowledge of attacks, protection, and counter-measures is important to the IT practitioner. The IT practitioner must comprehend and manage assurance and security measures within the enterprise. Topics include: operational issues, policies and procedures, attacks and related defense measures, risk analysis, backup and recovery, and the security of information.
This course provides a comprehensive overview of strategies, technologies, and best practices used to protect digital assets and ensure the confidentiality, integrity, and availability of information in modern computing environments. Students explore both foundational and advanced topics in cybersecurity, including threat modeling, risk assessment, access control, cryptographic systems, incident response, and security governance. Special attention is given to securing AI systems, APIs, and cloud-based infrastructures, as well as understanding the unique vulnerabilities introduced by machine learning pipelines and autonomous systems. Students will analyze real-world breaches, evaluate organizational security policies, and design mitigation strategies aligned with legal, ethical, and regulatory frameworks. Through labs, case studies, and applied projects, students will develop the practical skills needed to manage information assurance and defend enterprise systems against evolving cyber threats. The course further addresses the security of tool-calling AI agents in production, including prompt injection, tool and model supply-chain risk, least-privilege credential scoping, and human approval and audit trails for actions an agent takes on its own authority.
What changes
- Retitled from "Cybersecurity" to "Data Security and Information Assurance" per the workbook
- ML pipelines, retrieval stores, and agent tool calls treated as first-class attack surface
- Least-privilege tool scopes, sandboxing, and human approval gates bounding autonomous action
- AI-assisted detection and triage, with measured evaluation of agent-generated findings
- Governance extended to model and vendor provenance, privacy, and breach disclosure duty
6 proposed outcomes, mapped to 6 program outcomes
Each outcome below is written to be observable and assessable, and each is mapped to the program learning outcomes for which it produces evidence.
Students will be able to construct a threat model and risk assessment for an enterprise system containing machine learning pipelines, retrieval stores, and tool-calling agents, enumerating prompt-injection, tool and model supply-chain, and data-exfiltration paths and ranking them by likelihood, business impact, and residual risk.
Enumerating the prompt-injection, tool and model supply-chain, and data-exfiltration paths that run through an agent's tool calls is the security precondition for designing and integrating a domain-specific agent whose task execution is genuinely secure (PLO 2.2).
Students will be able to design a layered identity, access-control, cryptographic, and secrets-management control set for a distributed enterprise system, implementing least-privilege tool scopes, sandboxed execution, and human-in-the-loop approval gates that bound what an autonomous agent may do on its own authority.
Scoping an agent's credentials and tools to least privilege, sandboxing its execution, and gating consequential actions behind human approval are precisely the mechanisms by which a domain-specific agent is integrated for secure and flexible task execution (PLO 2.2).
Students will be able to construct a detection and triage capability that acquires, normalizes, and correlates security telemetry from host logs, cloud audit trails, API gateways, and agent execution traces, using embedding-based retrieval over prior incidents to enrich each alert for analyst review.
Acquiring, cleaning, storing, and correlating telemetry drawn from multiple heterogeneous sources through APIs and log databases is data acquisition applied to a real operational problem (PLO 2.1), and enriching alerts through embedding-based retrieval over an incident corpus is the use of LLM embeddings in structured enterprise deployment (PLO 6.1).
Students will be able to evaluate the reliability and failure modes of AI-assisted security tooling, including agent-generated detections, runbooks, and remediation code, against false-positive and false-negative rates, adversarial test cases, and a documented chain of human accountability for every action the system is permitted to take.
Measuring error rates, probing with adversarial cases, and naming who answers for machine-produced remediation supplies the transparency and accountability evidence for the outcome the workbook states twice, word for word, as PLO 1.1 under Christian Faith and as PLO 3.2 under Integrated Disciplinary Knowledge.
Students will be able to critique an organization's security and data-governance policy against its legal, regulatory, and ethical obligations, including privacy, breach disclosure, data minimization and retention, model and vendor provenance, and the unequal harm a breach imposes on the people whose data is held, recommending a revised policy and mitigation plan grounded in stewardship of data entrusted to the organization.
Judging policy against privacy, disclosure, provenance, and unequal-harm obligations, and recommending revisions on a stewardship rationale, is direct evidence for the outcome the workbook records twice in identical wording and with identical I/D/AE rows, as PLO 1.1 under Christian Faith and as PLO 3.2 under Integrated Disciplinary Knowledge.
Students will be able to communicate the findings, residual risk, and remediation plan from a security incident investigation, including what AI-assisted tooling and autonomous agent actions contributed to the incident and the privacy and breach-disclosure obligations it triggers, to the technical response team and to executive, legal, and non-technical stakeholders, in a written incident report and a live briefing that separate what is established from what remains uncertain.
Explaining what AI-assisted tooling and autonomous agent actions did during the incident carries the AI concepts and results, the privacy and breach-disclosure obligations carry the ethical considerations, the technical response team alongside executive, legal, and non-technical stakeholders supplies both audiences, and separating established fact from residual uncertainty is the clarity and responsibility PLO 5.1 requires.
Program outcomes this course reaches
Filled cells are program learning outcomes with at least one supporting course learning outcome in this course. Sparse coverage is expected — no single course carries all twelve.
The workbook maps this course too
The proposal workbook's assessment map already assigns program learning outcomes to this course. The outcomes above were written to cover it.
| Program outcome | Workbook level | In this draft |
|---|---|---|
| PLO 1.1 Ethical and Legal Integrity in AI | D | covered |
| PLO 2.1 Data Acquisition for Real Problems | I | covered |
| PLO 2.2 Domain-Specific AI Agents | I | covered |
| PLO 3.2 Ethical and Legal Integrity in AI | D | covered |
| PLO 5.1 Communicating AI to Any Audience | I | covered |
| PLO 6.1 LLMs in Industrial Settings | I | covered |
I = Introduced · D = Developed · AE = Assessed at Exit