{"id":22,"date":"2025-06-04T14:11:24","date_gmt":"2025-06-04T20:11:24","guid":{"rendered":"https:\/\/courses.cs.colostate.edu\/cs003\/?page_id=22"},"modified":"2026-08-02T00:39:47","modified_gmt":"2026-08-02T06:39:47","slug":"syllabus","status":"publish","type":"page","link":"https:\/\/courses.cs.colostate.edu\/cs559\/syllabus\/","title":{"rendered":"Syllabus"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Instructor: Yashwnt K. Malaiya<br>Email: malaiya\uff20colostate.edu<br>Phone: 970-491-7031 (messages)<br><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Course objectives<\/strong>: <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The course provides an integrated framework for Quantitative Evaluation and management of Security Risk. It draws from the fields of security (vulnerabilities, their discovery, and exploitation, security metrics), Reliability, Testing, and Risk evaluation. The integration provides a systematic terminology and a rigorous framework for evaluating mathematical or systematic risk by identifying its specific components, as well as the likely return on risk mitigation efforts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Quantitative data regarding the key aspects of security risk is becoming available. While the data is still limited, it can be used to assess the components of the security risk and potential mitigation approaches. The framework will allow additional data to be incorporated into the framework when it becomes available. In some cases, the available data may not be enough for rigorous modeling; however, it can be used to assess the magnitude of the risk components.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Framework: <\/strong>The published quantitative risk evaluation methods often focus on specific components of the risk. The course will provide an integrated perspective by combining diverse analyses and reports using a systematic framework. Since this is a developing field, the data, models, and techniques are still emerging. The course has a research component that requires the students to read and discuss assigned and self-selected papers and to work on a research project.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Topics:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Terms and framework<\/li>\n\n\n\n<li>Security Risk<\/li>\n\n\n\n<li>Probability and Modeling<\/li>\n\n\n\n<li>Deadlocks and resource management<\/li>\n\n\n\n<li>Vulnerabilities, lifecycle, metrics and databases<\/li>\n\n\n\n<li>Testing for vulnerabilities<\/li>\n\n\n\n<li>Research methodology<\/li>\n\n\n\n<li>Breach likelihood and cost<\/li>\n\n\n\n<li>Risk mitigation<\/li>\n\n\n\n<li>Vulnerability markets<\/li>\n\n\n\n<li>Emerging issues<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">The students will be assigned to read selected papers and discuss the contributions. A term research project is required. Potential topics will be identified.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Acknowledgement<\/strong>: This course was developed with support from the\u00a0<a href=\"https:\/\/cybersecurity.colostate.edu\/\">Cybersecurity Center<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Instructor: Yashwnt K. MalaiyaEmail: malaiya\uff20colostate.eduPhone: 970-491-7031 (messages) Course objectives: The course provides an integrated framework for Quantitative Evaluation and management of Security Risk. It draws from the fields of security (vulnerabilities, their discovery, and exploitation, security metrics), Reliability, Testing, and Risk evaluation. The integration provides a systematic terminology and a rigorous framework for evaluating mathematical [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-fullwidth.php","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","footnotes":""},"class_list":["post-22","page","type-page","status-publish","hentry","post-preview"],"taxonomy_info":[],"featured_image_src_large":false,"author_info":{"display_name":"admin","author_link":"https:\/\/courses.cs.colostate.edu\/cs559\/author\/admin_41g0qmxe\/"},"comment_info":0,"_links":{"self":[{"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/pages\/22","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/comments?post=22"}],"version-history":[{"count":5,"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/pages\/22\/revisions"}],"predecessor-version":[{"id":80,"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/pages\/22\/revisions\/80"}],"wp:attachment":[{"href":"https:\/\/courses.cs.colostate.edu\/cs559\/wp-json\/wp\/v2\/media?parent=22"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}