Case-based learning is a powerful pedagogical method of creating dialogue between theory and practice. CBL is particularly suited to executive learning as it instigates critical discussion and draws out relevant experiences. In this paper we used a real-world case to teach Information Security Management to students in Management Information Systems. The real-world case is described in a legal indictment, T-mobile USA Inc v Huawei Device USA Inc. and Huawei Technologies Co. LTD, alleging theft of intellectual property and breaches of contract concerning confidentiality and disclosure of sensitive information. The incident scenario is interesting as it relates to a business asset that has both digital and physical components that has been compromised through an unconventional cyber-physical attack facilitated by insiders. The scenario sparked an interesting debate among students about the scope and definition of security incidents, the role and structure of the security unit, the utility of compliance-based approaches to security, and the inadequate use of threat intelligence in modern security strategies.
翻译:以个案为基础的学习是建立理论和实践之间对话的强有力的教学方法。CBL特别适合执行人员学习,因为它激发了批判性讨论并吸取了相关经验。在这份文件中,我们用一个真实世界案例向管理信息系统的学生传授信息安全管理知识。真实世界案例在T-Movement USA Inc诉Huawei Droep AUS Inc.和Huawei Technology Co.LTD的法律起诉书中作了描述,指控知识产权被盗和违反关于保密和敏感信息披露的合同。事件情景很有意思,因为它涉及一个拥有数字和有形组成部分的商业资产,而这种资产因内部人员促成的非常规网络物理攻击而受到损害。情景引发了学生们就安全事件的范围和定义、安保单位的作用和结构、基于合规的安全办法的效用以及在现代安全战略中威胁情报使用不足等问题进行有趣的辩论。