Back close

Course Detail

Course Name Secure Systems Engineering
Course Code 26CY764
Program M. Tech. in Cyber Security
Credits 3
Campus Coimbatore

Syllabus

Syllabus

Balancing security and usability-User authentication mechanisms, Zero Trust Architecture, Identity and Access Management (IAM). Target environment hardening and secure application deployment. Threat Modeling -STRIDE, PASTA. Risk Assessment – CVSS v4.0, Attack trees. Security Testing – Common Vulnerabilities and Exploits, Application Security Testing- SAST, DAST, IAST, RASP, AI-Augmented Security: Using LLMs for code review vs. risks of AI-generated code, Fuzzing techniques-(Coverage-guided, Structure-aware). Software security economics-logging/monitoring and operational security aspects. Infrastructure Security-Infrastructure as Code (IaC- Terraform/CloudFormation/K8s manifests) Security, Container (Docker) Security, Cluster (Kubernetes) Security, eBPF for runtime protection. Software Supply Chain Security – SBOM (SPDX, CycloneDX), VEX, SCA, OSS Licensing Models, Policy-as-Code. Enhance Detection Engineering with Agile DevSecOps – SOC tech stack, EDR, SOAR, XDR, MDR, Chaos Engineering for resilience.

Objectives and Outcomes

Prerequisite

26CY613 Concepts in System Security

 

Course Outcome
Course Outcome Bloom’s Taxonomy Level
CO1 Comprehend secure design principles and threat modeling methodologies L4
CO2 Apply secure coding practices and AI-augmented vulnerability testing. Evaluate software supply chain risks using SBOMs and compliance models. L3
CO3 Analyze cloud-native infrastructure and container security architectures. Develop automated DevSecOps pipelines and operational resilience strategies. L4
CO-PO Mapping

CO-PO Mapping

CO/PO

PO 1 PO 2 PO 3 PO 4 PO 5 PO 6 PO 7 PO 8 PO 9 PO 10 PSO1 PSO2 PSO3
CO 1 2 3 3 2 3 2 1 2 2 2 2
CO 2 2 3 3 2 3 2 1 2 3 3 3
CO 3 2 3 3 2 3 2 1 2 3 3 3

Text Books / References

  1. Dotson, C. (2022). Practical Cloud Security: A Guide for Secure Design and Deployment. O’Reilly Media.
  2. S. Garfinkel and L. F. Cranor, Security and Usability: Designing Secure Systems That People Can Use, O’Reilly, 2008.
  3. L. Rice, Container Security: Fundamental Technology Concepts that Protect Containerized Applications. Sebastopol, CA, USA: O’Reilly Media, 2020.
  4. Bird, Jim. “DevOpsSec: Securing software through continuous delivery.” (2016).
  5. Tim Mather, Subra Kumaraswamy, Shahed: Cloud Security and Privacy: An Enterprise Perspective on Risks and Compliance, O’Reilly, 2009.
  6. Anderson, Ross J., Security Engineering: A Guide to Building Dependable Distributed Systems, John Wiley & Sons, 2010.
  7. M. Tehranipoor, and C. Wang, Introduction to Hardware Security and Trust, Springer, 2011.
  8. C. W. Axelrod, Engineering Safe and Secure Software Systems, Artech House, 2013.
  9. Antonio Borghesi and Barbara Gaudenzi: Risk Management: How to Assess, Transfer and Communicate Critical Risks, Springer, 2013.
  10. Steve WatkinsAn Introduction to Information Security and ISO27001:2013: A Pocket Guide, 2nd Edition, IT Governance Publishing, 2013.

DISCLAIMER: The appearance of external links on this web site does not constitute endorsement by the School of Biotechnology/Amrita Vishwa Vidyapeetham or the information, products or services contained therein. For other than authorized activities, the Amrita Vishwa Vidyapeetham does not exercise any editorial control over the information you may find at these locations. These links are provided consistent with the stated purpose of this web site.

Admissions Apply Now