MSc Information Assurance
Master Audit, Security Governance, and Threat Mitigation
About This Program
Program Description
The Master of Science in Information Assurance prepares graduates to become advanced information assurance professionals, information security specialists, cybersecurity governance practitioners, security consultants, risk analysts, security auditors, compliance specialists, security architects, researchers, and information security leaders capable of protecting critical information assets and assuring the security and reliability of digital environments.
The programme builds upon students' existing knowledge of computing, information technology, information security, cybersecurity, networking, software engineering, business, risk management, or related disciplines and develops this knowledge to an advanced postgraduate level.
Students begin by examining the strategic and technical foundations of information assurance. They analyse information assets, security threats, vulnerabilities, risks, security objectives, control environments, and assurance requirements. Students develop the ability to evaluate information-security challenges from both technical and organizational perspectives.
Advanced study of information security governance and security architecture enables students to evaluate organizational security environments and develop appropriate security structures. Students examine security policies, governance models, defence-in-depth, zero-trust principles, identity-centric security, network segmentation, access controls, secure infrastructure, security monitoring, and resilient information-system design.
The programme provides advanced study of information-security risk management. Students learn to identify information assets, threats, vulnerabilities, risks, and potential business impacts. They evaluate risk likelihood and consequences, develop risk-treatment strategies, prioritize security investments, and assess residual risk. The programme emphasizes the alignment of security risk management with organizational objectives and decision-making.
Students develop advanced capabilities in security controls and information assurance assessment. They examine administrative, technical, and physical controls and evaluate whether controls are appropriately designed, implemented, operated, and monitored. Students learn to identify control deficiencies, assess control effectiveness, document findings, and develop practical remediation recommendations.
Security governance, risk, and compliance form a central component of the programme. Students examine organizational security policies, governance structures, regulatory requirements, industry standards, control frameworks, compliance obligations, risk reporting, third-party security, and security performance measurement. They learn how governance mechanisms support accountability and effective information protection.
The programme develops advanced knowledge of IT audit and security assurance. Students examine audit planning, evidence collection, control testing, audit methodologies, security assessments, findings, corrective actions, assurance reporting, and follow-up processes. Practical activities enable students to assess information systems and determine whether security controls meet defined organizational and regulatory requirements.
Students develop specialist knowledge in identity and access management. They examine authentication, authorization, access-control models, identity lifecycle management, multi-factor authentication, privileged access management, identity federation, role-based access control, and access governance. Students evaluate how identity controls contribute to information assurance and reduce unauthorized access.
The programme addresses data security, privacy, and information protection. Students examine data classification, information handling, data-loss prevention, encryption, privacy principles, data protection, retention, secure disposal, and privacy risk. They learn to develop strategies for protecting sensitive and critical information throughout its lifecycle.
Business continuity, disaster recovery, and cyber resilience are examined in the context of information assurance. Students evaluate organizational dependencies, critical information systems, business impacts, recovery requirements, backup strategies, recovery architectures, continuity plans, crisis-management processes, and resilience measures. They learn how organizations can maintain critical operations while responding to disruptive events.
The programme incorporates advanced study of security architecture and secure information systems. Students evaluate enterprise architectures, infrastructure security, network controls, application security, cloud environments, endpoint protection, secure communications, and security-by-design principles. They learn to evaluate whether technology environments provide appropriate protection for organizational information assets.
Students develop an understanding of cloud, mobile, Internet of Things, and distributed-system assurance. They assess the information-security and assurance implications of modern technology environments, including cloud services, virtualized systems, APIs, mobile platforms, connected devices, and distributed infrastructures.
The programme provides advanced study of application and software security. Students investigate secure software-development principles, application vulnerabilities, authentication and authorization weaknesses, API security, software dependencies, secure development practices, software supply-chain risks, and application security controls. They learn how assurance requirements can be incorporated throughout the software development lifecycle.
Cryptography and information protection technologies are examined at an advanced level. Students explore encryption, hashing, digital signatures, public-key infrastructure, key management, secure communications, and cryptographic applications. They evaluate how cryptographic mechanisms contribute to confidentiality, integrity, authenticity, and non-repudiation.
Students examine security monitoring, incident management, and information-assurance response. They learn how organizations identify security events, assess incidents, collect relevant evidence, coordinate response activities, contain security risks, recover affected systems, and conduct post-incident reviews. The programme emphasizes the relationship between incident management, risk management, governance, and continuous assurance.
The programme develops advanced understanding of information-security policies, standards, procedures, and security culture. Students learn how organizations establish security requirements, communicate responsibilities, measure compliance, promote security awareness, and develop a culture of responsible information protection.
Students examine privacy, cyber law, ethics, and professional practice. Topics include data protection, privacy obligations, cybercrime, responsible security practices, information rights, legal requirements, professional responsibilities, ethical decision-making, and the governance of security activities.
The programme addresses third-party, supply-chain, and vendor security assurance. Students evaluate the risks associated with external service providers, technology suppliers, cloud providers, contractors, and business partners. They learn to assess security requirements, evaluate supplier controls, monitor third-party risks, and develop assurance mechanisms for external relationships.
Information assurance metrics, analytics, and reporting enable students to evaluate security performance using appropriate measures and evidence. Students examine security metrics, key risk indicators, control effectiveness measures, audit findings, compliance reporting, risk dashboards, and executive security reporting.
The programme places strong emphasis on information-assurance research and innovation. Students develop advanced research skills, including problem formulation, literature analysis, research design, data collection, assurance assessment, evaluation, critical analysis, and academic communication. They learn to investigate emerging information-security challenges and evaluate new assurance approaches.
The Information Assurance Research Project or Capstone Project provides students with an opportunity to conduct an independent investigation into a significant information-assurance problem. Under academic supervision, students identify a research or applied assurance problem, evaluate existing approaches, design and implement an appropriate methodology or assessment, analyse findings, and communicate their recommendations through a substantial academic and professional report.
Students may apply their knowledge to information-assurance challenges across finance, healthcare, education, government, telecommunications, energy, manufacturing, retail, transportation, professional services, cloud computing, software development, and other information-intensive industries.
Graduates are equipped for advanced professional and technical careers in information assurance, information security, cybersecurity governance, security risk management, IT audit, security compliance, security assurance, data protection, security consulting, security architecture, identity and access management, cyber resilience, and information security management. The programme also provides a foundation for professional certifications, doctoral research, academic careers, and specialist security roles.
Specializations
- Cybersecurity Governance and Compliance
- Information Security Architecture
- Security Controls and Assessment
- Data Security and Privacy
- Identity and Access Management
- Cloud and Infrastructure Assurance
- Third-Party and Supply-Chain Security
- Security Operations and Incident Management
- Cryptography and Information Protection
- Security Risk Management
- IT Audit and Security Assurance
Admissions
Entry Requirements
Applicants should hold a bachelor's degree from an accredited university or a recognized equivalent qualification.
Applicants should demonstrate competence in English.
Applicants should satisfy the university's postgraduate admission requirements.
Applicants should have an academic or professional background in computer science, information technology, software engineering, information systems, cybersecurity, information security, networking, engineering, mathematics, risk management, or a related discipline.
Applicants should demonstrate foundational knowledge of computing, information systems, computer networks, operating systems, databases, mathematics, information security, or related concepts relevant to postgraduate study in Information Assurance.
Applicants with relevant professional experience in information technology, information security, cybersecurity, network administration, systems administration, IT governance, risk management, auditing, compliance, or related fields may also be considered, subject to the university's admission requirements.
Applicants may be required to satisfy any additional departmental requirements for admission into the Master of Science in Information Assurance program.
What You'll Achieve
Learning Outcomes
Critically evaluate advanced principles, concepts, theories, and practices in information assurance.
Analyse information assets, threats, vulnerabilities, risks, and security requirements within complex organizational environments.
Evaluate information-security risks across enterprise, cloud, network, application, and information environments.
Design and evaluate security policies, standards, procedures, and governance mechanisms.
Evaluate enterprise security architectures and recommend appropriate information-protection controls.
Apply identity and access-management principles to protect organizational information and systems.
Evaluate authentication, authorization, privileged access, identity lifecycle, and access-governance controls.Evaluate third-party, supplier, vendor, and supply-chain security risks.
Develop security-assurance strategies for managing external technology and service providers.
Apply security metrics, key risk indicators, audit results, and assurance evidence to support organizational decision-making.
Evaluate cybersecurity governance, compliance, audit, assurance, and control frameworks.
After Graduation
Career Opportunities
A Closer Look
Ready to Enrol in MSc Information Assurance?
Take the first step. Apply today and our admissions team will guide you through every stage.
Admissions Team
24/7 Support
Secure Process