Skip to main content

Auditing, Penetration Testing and Red Teaming (5 cr)

Code: TTC6550-3007

General information


Enrollment
20.11.2023 - 04.01.2024
Registration for the implementation has ended.
Timing
08.01.2024 - 30.04.2024
Implementation has ended.
Number of ECTS credits allocated
5 cr
Local portion
5 cr
Mode of delivery
Face-to-face
Unit
School of Technology
Campus
Lutakko Campus
Teaching languages
Finnish
Seats
0 - 35
Degree programmes
Bachelor's Degree Programme in Information and Communications Technology
Teachers
Joonatan Ovaska
Groups
TTV21S1
Tieto- ja viestintätekniikka (AMK)
TTV21S2
Tieto- ja viestintätekniikka (AMK)
TTV21S3
Tieto- ja viestintätekniikka (AMK)
TTV21S5
Tieto- ja viestintätekniikka (AMK)
TTV21SM
Tieto- ja viestintätekniikka (AMK)
Course
TTC6550

Realization has 5 reservations. Total duration of reservations is 10 h 0 min.

Time Topic Location
Tue 05.03.2024 time 13:30 - 15:30
(2 h 0 min)
Auditointi, Penetraatiotestaus ja Red Team -toiminta TTC6550-3007
P2_D330 Ohjelmointiluokka
Tue 12.03.2024 time 13:30 - 15:30
(2 h 0 min)
Auditointi, Penetraatiotestaus ja Red Team -toiminta TTC6550-3007
P2_D330 Ohjelmointiluokka
Tue 19.03.2024 time 13:30 - 15:30
(2 h 0 min)
Auditointi, Penetraatiotestaus ja Red Team -toiminta TTC6550-3007
Verkko/Online (KYHA)
Tue 26.03.2024 time 13:30 - 15:30
(2 h 0 min)
Auditointi, Penetraatiotestaus ja Red Team -toiminta TTC6550-3007
P2_D330 Ohjelmointiluokka
Tue 02.04.2024 time 13:30 - 15:30
(2 h 0 min)
Auditointi, Penetraatiotestaus ja Red Team -toiminta TTC6550-3007
P2_D330 Ohjelmointiluokka
Changes to reservations may be possible.

Evaluation scale

0-5

Objective

The purpose of the course
You will learn the principles of auditing, penetration testing and Red Teaming.

Competences
EUR-ACE: Knowledge and understanding 
EUR-ACE: Engineering practice 
EUR-ACE: Multidisciplinary competences 
EUR-ACE: Communication and team-working 

Learning objective of the course
After completing the course the student knows the most commonly used evaluation and auditing principles. The student is also able to apply security testing methods, techniques and tools in practice. Additionally, the student knows the basic concepts and implementation criteria of security testing.

Content

Auditing
- data security and data protection
- classification of data and protection methods
- data security assessment and auditing
- standardization and data security standards
- certification and accreditation
- data security testing and testing process
- data security testing methods and techniques

Penetration testing
- data security testing of data networks
- data security testing of systems
- data security testing of client applications
- data security testing of server applications
- vulnerability management

Red Teaming:
- operational models
- model for outline of requirements
- Red Teaming examples
- Threat modelling basics

Materials

Materials in the e-learning environment.

Teaching methods

- lectures
- independent study
- distance learning
- webinars
- small group learning
- exercises
- learning tasks
- seminars

Employer connections

- visiting lecturers
- projects

Exam schedules

The possible date and method of the exam will be announced in the course opening.

Completion alternatives

The admission procedures are described in the degree rule and the study guide. The teacher of the course will give you more information on possible specific course practices.

Student workload

One credit (1 Cr) corresponds to an average of 27 hours of work.

- lectures 52 h
- exercises 10 h
- assignment 40 h
- independent study 30 h
- company visits 3 h
Total 135 h

Assessment criteria, satisfactory (1)

Sufficient 1: The student knows the theory sufficiently and recognizes some parts of auditing, penetration testing and Red Teaming. The student is able to plan and implement parts of data security auditing.

Satisfactory 2: The student knows the theory satisfactorily and recognizes parts of auditing, penetration testing and Red Teaming. The student is able to plan and implement parts of data security auditing.

Assessment criteria, good (3)

Good 3: The student knows the theory well and recognizes parts of auditing, penetration testing and Red Teaming. The student is able to plan and implement parts of data security auditing.

Very good 4: The student knows the theory very well and recognizes parts of auditing, penetration testing and Red Teaming. The student is able to plan and implement a data security audit.

Assessment criteria, excellent (5)

Excellent 5: The student knows the theory excellently and recognizes extensively parts of auditing, penetration testing and Red Teaming. The student is able to plan and implement a data security audit.

Qualifications

Basics of linux, cyber security, data networks

Go back to top of page