0% found this document useful (0 votes)
4 views29 pages

Elective Syllabus Compiled

The document outlines the course structure for Cyber Security and Generative Artificial Intelligence at Pokhara University, detailing course codes, objectives, content, methods of instruction, and evaluation systems. The Cyber Security course focuses on principles such as risk management, cryptography, and ethical hacking, while the Generative AI course emphasizes foundational programming skills, large language models, and ethical considerations. Both courses aim to equip students with practical skills and theoretical knowledge relevant to their respective fields.

Uploaded by

karnaachal07
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views29 pages

Elective Syllabus Compiled

The document outlines the course structure for Cyber Security and Generative Artificial Intelligence at Pokhara University, detailing course codes, objectives, content, methods of instruction, and evaluation systems. The Cyber Security course focuses on principles such as risk management, cryptography, and ethical hacking, while the Generative AI course emphasizes foundational programming skills, large language models, and ethical considerations. Both courses aim to equip students with practical skills and theoretical knowledge relevant to their respective fields.

Uploaded by

karnaachal07
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Pokhara University

Faculty of Science and Technology

Course Code: Elective Full marks: 100


Course title: Cyber Security (3-1-2) Pass marks: 45
Nature of the course: Theory & Practical Total Periods: 45
Level: Bachelor Program: BE

Course Description
This course provides an in-depth study of cybersecurity principles, including security threats,
risk management, cryptographic techniques, network security, and ethical hacking. It explores
web security and system protection mechanisms, enabling students to understand and mitigate
cyber threats. The course combines theoretical concepts with hands-on practical work to equip
students with real-world cybersecurity skills.

General Objectives
The course is designed with the following objectives:
 To understand fundamental concepts of cybersecurity, including threats,
vulnerabilities, and risk management.
 To explore cryptographic principles and their application in securing data and
communication.
 To analyze network security mechanisms such as firewalls, intrusion detection
systems (IDS), and VPNs.
 To introduce ethical hacking and penetration testing.
 To learn about web security threats and protection strategies.
 To examine legal and ethical aspects of cybersecurity and data privacy.
 To provide hands-on experience with cybersecurity tools and techniques.

Methods of Instruction
The course will be delivered through a combination of:
 Lectures: Providing theoretical foundations of cybersecurity.
 Tutorials: Discussion-based learning and case studies.
 Practical Work: Hands-on exercises on cybersecurity tools, encryption, and ethical
hacking.
 Quizzes & Assignments: Evaluating students’ understanding of key concepts.
 Group Discussions & Presentations: Engaging students in real-world cybersecurity
issues.
 Project Work: Implementing security solutions in real-world scenarios.

Contents in Detail with Specific Objectives


Specific Objective Content
Students will understand the importance of Unit 1: Introduction to Cybersecurity (7 hrs)
cybersecurity, the challenges faced, key 1.1 Understanding cybersecurity: Definition,
security principles (CIA), risk management importance, and challenges.
frameworks, best practices in securing 1.2 Cyber threats, vulnerabilities, and attack
information systems, various types of vectors.
malware and antivirus solutions. 1.3 Security principles: Confidentiality, Integrity,
and Availability (CIA).
1.4 Risk assessment and management
frameworks.
1.5 Malware types: Viruses, worms, ransomware,
trojans.
1.6 Antivirus and endpoint security solutions.

Students will learn about cryptographic Unit 2: Cryptography and Data Security(8 hrs)
techniques, including symmetric/asymmetric 2.1 Introduction to cryptography: Symmetric vs.
encryption, cryptographic algorithms, hashing asymmetric encryption.
techniques, digital signatures, and secure 2.2 Cryptographic algorithms: DES, AES, RSA,
communication protocols like SSL/TLS. ECC.
2.3 Hashing techniques: MD5, SHA-256.
2.4 Digital signatures and certificates.
2.5 Secure communication protocols: SSL/TLS.

Understanding of network security Unit 3: Network Security (7 hrs)


fundamentals, secure network design, VPNs, 3.1 Network security fundamentals: Firewalls,
wireless security standards, and tools like IDS and IPS.
Nmap and Wireshark for network scanning 3.2 Secure network architecture and design.
and penetration testing. 3.3 VPNs and secure remote access.
3.4 Wireless security and encryption standards
(WPA, WPA2, WPA3).
3.5 Network scanning and penetration testing
tools (Nmap, Wireshark).

Students will Gain knowledge of ethical Unit 4: Ethical Hacking and Penetration
hacking methodologies, common attack Testing (7 hrs)
techniques, the Metasploit framework, social 4.1 Overview of ethical hacking and penetration
engineering, and incident response in testing.
penetration testing. 4.2 Common hacking techniques: SQL injection,
cross-site scripting (XSS), phishing.
4.3 Metasploit framework and exploit
development.
4.4 Social engineering attacks and
countermeasures.
4.5 Incident response and digital forensics.

Students will learn about web security Unit 5: Web Security and Application
vulnerabilities, secure coding practices, Web Protection (8 hrs)
Application Firewalls (WAFs), secure 5.1 Web security vulnerabilities: OWASP Top 10.
authentication, session management, and 5.2 Secure coding practices for web applications.
lessons from major web security breaches. 5.3 Web application firewalls (WAF).
5.4 Secure authentication and session
management.
5.5 Case studies of major web security breaches.
Students will learn about key cybersecurity Unit 6: Cybersecurity Laws, Ethics, and
laws, ethical issues, data privacy compliance, Compliance (8 hrs)
digital evidence handling, and case studies on 6.1Cyber laws and regulations (GDPR, NIST,
law enforcement in cybersecurity. ISO 27001, Electronic Transaction Act, National
ICT Policy ).
6.2Ethical issues in cybersecurity.
6.3Data privacy and compliance.
6.4Digital evidence and legal procedures.
6.5Case studies on cybersecurity law
enforcement.

List of Tutorials
The following tutorial activities of 15 hours per group of maximum 24 students should be
conducted to cover all the required contents of this course.
1. Identifying security threats and vulnerabilities in real-world scenarios.
2. Implementing symmetric and asymmetric encryption techniques.
3. Understanding cryptographic hashing and digital signatures.
4. Configuring firewalls and network security tools.
5. Conducting penetration testing using Kali Linux.
6. Analyzing network traffic with Wireshark.
7. Performing web security assessments (SQL injection, XSS).
8. Setting up secure authentication mechanisms.
9. Configuring security policies in operating systems.
10. Understanding social engineering attacks through case studies.
11. Developing a secure web application.
12. Conducting an incident response exercise.
13. Studying cybersecurity compliance and legal issues.
14. Group discussion on emerging cybersecurity trends.

Practical Work
1. Hands-on cryptography: Implementing AES and RSA encryption.
2. Network security lab: Configuring firewalls, IDS, and VPNs.
3. Penetration testing: Using Kali Linux tools (Metasploit, Burp Suite).
4. Web security testing: Identifying vulnerabilities in web applications.
5. Forensic analysis: Extracting and analyzing digital evidence.
6. Configuring Linux and Windows security settings.
7. Wireshark lab: Analyzing packet captures.
8. Social engineering simulation: Awareness training on phishing and scams.
9. Project work: Developing a real-world cybersecurity solution.

Evaluation System and Students' Responsibilities


Internal Evaluation (50 Marks)
Internal Evaluation
In addition to the formal end-semester exam(s), the internal (formative) evaluation of a student
may consist of quizzes, assignments, lab reports, projects, class participation and presentation
etc. The tabular presentation of the internal evaluation is as follows. The components may differ
according to the nature of the subjects.

Internal Evaluation Weight Marks External Evaluation Marks


Theory 30 Semester-End Examination 50
Attendance and Class 10%
Participation
Assignments 20%
Presentations/Quizzes 10%
Internal Assessment 60%
Practical 20
Attendance and Class 10%
Participation
Lab Report/ Project 20%
Report
Practical Exam/ Project 40%
Work
Viva 30%
Total Internal 50
Full Marks: 50+50=100

Students’ Responsibility
Each student must secure at least 45% marks in internal evaluation with 80% attendance in the
class in order to appear in the semester-end examination. Failing to get such a score will be
equated with NOT QUALIFIED (NQ) and the student will not be eligible to appear in the End-
Semester examinations. Students are advised to attend all the classes and complete all the
assignments within the specified time period. Failure of a student to attend a formal exam, quiz,
test, etc. won’t qualify him/her for re-exam. Students are required to complete all the
requirements defined for the completion of the course

Prescribed Books and References

Prescribed Books
1. Charles J. Brooks, Christopher Grow, Philip Craig, Donald Short, Cybersecurity
Essentials, 1st Edition, Wiley
2. William Stallings, Cryptography and Network Security: Principles and Practice, 7th
Edition, Pearson
3. Michael T. Simpson, Kent Backman, James Corley, Hands-On Ethical Hacking and
Network Defense, 3rd Edition, Cengage Learning
4. Michael Sikorski, Andrew Honig, Practical Malware Analysis: The Hands-On Guide
to Dissecting Malicious Software, 1st Edition, No Starch Press
References
1. Michael E. Whitman, Herbert J. Mattord, Principles of Information Security, 7th
Edition, Cengage Learning
2. Raef Meeuwisse, Cybersecurity for Beginners, Updated Edition (2023), Cyber
Simplicity Ltd
3. Bruce Schneier, Applied Cryptography: Protocols, Algorithms, and Source Code in C,
2nd Edition, Wiley
4. Kevin D. Mitnick, William L. Simon, The Art of Deception: Controlling the Human
Element of Security, 1st Edition, Wiley
5. Dafydd Stuttard, Marcus Pinto, The Web Application Hacker's Handbook: Finding
and Exploiting Security Flaws, 2nd Edition, Wiley
6. Jonathan Clough, Principles of Cybercrime, 2nd Edition, Cambridge University Press
7. OWASP Web Security Testing Guide ([Link]).
Pokhara University
Faculty of Science and Technology

Course No.: Elective Full marks: 100

Course title: Generative Artificial Intelligence (3-1-2) Pass marks: 45

Nature of the course: Theory/Tutorial/Practical Time per period: 1 hour

Year: Total periods: 45

Level: Undergraduate Program: BE Computer/IT/Software

Course Description
This course offers an in-depth introduction to Generative Artificial Intelligence (GenAI),
combining foundational programming skills with cutting-edge developments in large language
models and AI application frameworks. Students will begin by mastering Python and essential
data libraries, then delve into the architecture of LLMs, advanced prompting techniques, and
tools like LangChain for building complex generative systems. The course also covers Retrieval
Augmented Generation (RAG), ethical considerations in AI, and emerging topics such as
multimodal and agentic systems. By the end of the course, students will be equipped to design,
build, and critically evaluate GenAI applications across a range of contexts.

General Objectives
The course is designed with the following objectives:

1. Build foundational skills in Python and essential data libraries for AI development.
2. Understand the architecture, training, and evolution of large language models in
generative AI.
3. Apply prompt engineering, LangChain, and RAG techniques to build and optimize
GenAI applications.
4. Analyze ethical, social, and practical implications of GenAI in real-world contexts.
Methods of Instruction

Contents in detail with specific objectives


Specific Objectives Contents

Develop foundational Python skills and Unit 1: Introduction to Generative AI and


familiarize with core data libraries and tools Python Fundamentals (7 hrs)
useful for generative AI development. 1.1 Evolution of AI and Emergence of
Generative AI
1.2 Python Syntax and Data Types
1.3 Control Structures and Functions in
Python
1.4 Introduction to NumPy for Numerical
Operations
1.5 Pandas for Data Manipulation and
Analysis
1.6 Data Visualization with Matplotlib
1.7 Introduction to FastAPI for API
development

Unit 2: Foundations of Large Language


Familiarize with the architecture, types, and Models (6 hrs)
training methodologies of modern large 2.1 Transformer Architecture and Attention
language models. Mechanisms
2.2 Key LLM Types: GPT, BERT, LLaMA,
2.3 Training Methodologies: Pre-training and
Fine-tuning

Implement the zero-shot and few shot prompts Unit 3: Prompt Engineering Fundamentals
to build effective Gen AI applications. (8 hrs)
3.1 Introduction to Prompt Engineering
3.2 Anatomy of Effective Prompts
3.3 Zero-shot Learning Techniques
3.4 Few-shot Learning and Examples
3.5 Chain-of-Thought Prompting
3.6 Role Prompting and System Instructions
3.7 Prompt Templates and Frameworks
3.8 Case Study: Interactive Prompt Workshop
with LLM models

Unit 4: LangChain Framework and


Build complex LLM-based applications using Applications (8 hrs)
the LangChain framework by leveraging
4.1 LangChain Architecture and Components
chains, memory, and tool integration.
4.2 Chains and Sequence Processing
4.3 Prompt Templates and LLM Integration
4.4 Memory Systems in LangChain
4.5 Agents and Tools Implementation
4.6 Document Loading and Text Splitting
4.7 Building Conversational Applications
4.8 Case Studies of LangChain Applications

Unit 5: Retrieval Augmented Generation


Implement context-aware LLM systems using (RAG) (8 hrs)
vector embeddings, similarity search, and
5.1 Introduction to Retrieval Augmented
evaluation metrics in RAG pipelines.
Generation
5.2 Understanding Tokens and Token
Limitations
5.3 Vector Embeddings: Principles and
Generation
5.4 Vector Databases: Pinecone, Chroma,
5.5 Chunking Strategies and Metadata
5.6 Similarity Search and Retrieval
Mechanisms
5.7 Hybrid Search Methods
5.8 Re-ranking Techniques
5.9 Evaluation Metrics: BLEU, Context
precision, recall, faithfulness, relevance

Unit 6: Ethical and Responsible AI (4 hrs)


Analyze ethical challenges in generative AI
6.1 Introduction to Ethics in Generative AI
and apply responsible AI practices across the
6.2 Sources and Impacts of Bias in LLMs
model lifecycle.
6.3 Fairness, Representation, and Social Harm
6.4 Explainability and Transparency
Challenges
6.5 Model Misuse, Hallucinations, and
Jailbreak Risks
6.6 Data Privacy, Consent, and Legal
Considerations (e.g., GDPR, AI Act)

Unit 7: Advanced Topics in Generative AI


Familiarize students with emerging trends in (4 hrs)
generative AI, including multimodal systems,
7.1 Fundamentals of Multimodal AI
agentic models, and advanced fine-tuning
7.2 Agentic AI Systems
techniques.
7.3 Emerging Research Directions
7.4 Self-hosting LLMs
7.5 Finetuning LLMs

List of Tutorials
The following tutorial activities of 15 hours per group of maximum 24 students should be
conducted to cover all the required contents of this course.
1. Python Environment Setup & Basics: Installing Python, Jupyter, and essential libraries;
basic syntax and data types practice.
2. NumPy & Pandas Fundamentals: Core operations with NumPy arrays and Pandas
DataFrames for AI data preparation.
3. Data Visualization & FastAPI: Creating visualizations with Matplotlib and building
simple APIs with FastAPI.
4. LLM API Integration: Making calls to popular LLM APIs and handling responses.
5. Zero-shot Prompting: Crafting and testing effective zero-shot prompts across various
tasks.
6. Few-shot Prompting: Implementing few-shot learning techniques with examples.
7. Chain-of-Thought Prompting: Developing prompts for complex reasoning tasks.
8. Role Prompting & System Instructions: Creating specialized prompts for different
contexts and roles.
9. Prompt Templates & Frameworks: Building reusable prompt structures and formats.
10. LangChain Basics: Setting up LangChain environment and implementing basic chains.
11. LangChain Memory Systems: Implementing different memory types for contextual
conversations.
12. LangChain Agents & Tools: Building agents that can use tools to solve multi-step
problems.
13. RAG Document Processing: Techniques for processing, chunking, and preparing
documents.
14. Vector Embeddings & Databases: Working with embeddings and configuring vector
databases.
15. RAG Pipeline Implementation: Building and testing complete RAG systems.

Practical Work
1. Python Data Science Portfolio (5 hours)
a. Comprehensive data analysis project using NumPy, Pandas, and Matplotlib
b. Creation of reusable data processing functions for AI applications
c. Integration with FastAPI to create a simple data service
2. Prompt Engineering Showcase (6 hours)
a. Develop and document a collection of optimized prompts using a single LLM
b. Implement zero-shot, few-shot, and chain-of-thought approaches
3. Conversational AI Assistant (6 hours)
a. Develop a command-line AI assistant using LLM APIs
b. Implement context management and conversation history
c. Add domain-specific capabilities through prompt engineering
4. Advanced LangChain Application (7 hours)
a. Create a full-featured application using LangChain framework
b. Implement chains, agents, memory systems, and tool integration
5. Comprehensive RAG System (6 hours)
a. Develop an end-to-end RAG pipeline for domain-specific documents
b. Implement chunking strategies and similarity search
c. Create a simple interface for querying the knowledge base

Evaluation system and students' responsibilities

Internal Evaluation
In addition to the formal end-semester exam(s), the internal (formative) evaluation of a student
may consist of quizzes, assignments, lab reports, projects, class participation and presentation
etc. The tabular presentation of the internal evaluation is as follows. The components may differ
according to the nature of the subjects.
Internal Evaluation Weight Marks External Evaluation Marks

Theory

Attendance & Class Participation

Assignments

Presentations/Quizzes

Internal Assessment

Practical

Attendance & Class Participation

Lab Report/Project Report

Practical Exam/Project Work

Viva

Total Internal

Student requirements:
Each student must secure at least 45% marks in internal evaluation with 80% attendance in the
class in order to appear in the semester-end examination. Failing to get such a score will be equated
with NOT QUALIFIED (NQ) and the student will not be eligible to appear in the End- Semester
examinations. Students are advised to attend all the classes and complete all the assignments within
the specified time period. Failure of a student to attend a formal exam, quiz, test, etc. won’t qualify
him/her for re-exam. Students are required to complete all the requirements defined for the
completion of the course

Prescribed Books and References


1. Prompt Engineering Guide by West, H., & Bommasani, R. (2023). GitHub.
[Link]
2. Language models are few-shot learners by Brown, T. B., et al. (2020). arXiv preprint
arXiv:2005.14165. [Link]
3. Retrieval-augmented generation for knowledge-intensive NLP tasks by Lewis, P., et al. (2020).
arXiv preprint arXiv:2005.11401. [Link]
4. LLaMA: Open and efficient foundation language models by Touvron, H., et al. (2023). arXiv
preprint arXiv:2302.13971. [Link]
5. Python for Data Analysis: Data Wrangling with pandas, NumPy, and Jupyter by McKinney, W.
(2022). [Link]
6. FastAPI Cookbook: Develop high-performance APIs and web applications with Python (2023)
7. The Big Book of Generative AI by Databricks (2025).
8. Rothman, D. (2024). RAG-Driven Generative AI: Build custom retrieval augmented generation
pipelines with LlamaIndex, Deep Lake, and Pinecone. Packt.
Pokhara University
Faculty of Science and Technology

Course No.: Full marks: 100


Course title: Information System Audit (3-1-0) Pass marks: 45
Nature of the course: Theory Total Lectures: 45 hrs.
Level: Bachelors Program: BE

1. Course Description
The Information System Audit course for undergraduate students provides an in-depth understanding
of auditing principles, methodologies, and best practices for assessing the security, integrity, and
compliance of information systems. The course covers risk assessment, control frameworks, IT
governance, regulatory compliance, and emerging threats in cybersecurity. Students will gain hands-
on experience in auditing IT infrastructure, applications, and processes through case studies and
practical exercises. This course covers different concepts of Information Systems Auditing including
basics, hardware and software security issues, information systems audit and conducting IS audit, risk-
based systems audit, business continuity and disaster, auditing in the ICT environment, and security
testing.

2. General Objectives

 To develop a foundational understanding of information systems auditing principles, processes,


and methodologies.
 To explore risk-based auditing approaches within ICT environments.
 To examine the role of Governance, Risk, and Compliance (GRC) in information systems
auditing.
 To understand the importance of business continuity and disaster recovery in audit planning.
 To gain familiarity with security testing tools, vulnerability assessment, and penetration testing
techniques.
 To analyze emerging trends and challenges in the field of information systems auditing.

3. Methods of Instruction

Lecture, Discussion, Readings, Case Studies and Group Workshops


4. Contents in Detail.

Specific Objectives Contents

Acquire knowledge of the Unit 1: Overview of Systems Audit (8 Hrs.)


fundamental concepts of 1.1 Information Systems Audit and Information Systems Auditor
Information System Audit and IT 1.2 Legal Requirements of an Information Systems Audit
Audit Frameworks, with an 1.3 Systems Environment and Information Systems Audit
emphasis on widely recognized 1.4 Information Systems Assets and Classification of Controls
standards such as ISO 27001, 1.5 Information Systems Audit Coverage
NIST, and MITRE. 1.6 IT Audit Framework, ISO 27001, NIST Cyber Security
Framework and MITRE
Gain knowledge of the key Unit 2: Hardware and Software Security Issues (8 Hrs.)
concepts related to hardware 2.1 Hardware Security Objective
and software security issues 2.2 Peripheral Devices and Storage Media
encountered during an 2.3 Authentication Devices
Information System Audit. 2.4 Hardware Acquisition, Hardware Maintenance and
Management of Obsolescence
2.5 Disposal of Equipment; Problem Management; Change
Management
2.6 Network and Communication Issues.
2.7 Overview of Types of Software; Elements of Software
Security
2.8 Control Issues during Installation and Maintenance
Gain knowledge of the Unit 3: Information Systems Audit Requirements (8 Hrs.)
requirements of Information 3.1 Information Systems Control Objectives; Information
System Audit in relation to Systems Audit Objectives;
system controls, log 3.2 System Effectiveness and Efficiency
management, and evidence 3.3 Information Systems Abuse
collection processes. 3.4 Asset Safeguarding Objective and Process
3.5 Evidence Collection and Evaluation
3.6 Logs and Audit Trails as Evidence
3.7 IT Audit Standard and Regulatory Requirements
Gain knowledge of the concept Unit 4: Conducting an Information Systems Audit (10 Hrs.)
of Information System Auditing, 4.1 Audit Program and Audit Plan
including its purpose, scope, and 4.2 Audit Procedures and Approaches
role in evaluating and ensuring 4.3 System Understanding and Review
the effectiveness of IT controls 4.4 Compliance Reviews and Tests
and processes. 4.5 Substantive Reviews and Tests
4.6 Audit Tools and Techniques
4.7 Sampling Techniques
4.8 Audit Questionnaire; Audit Documentation; Audit Report
4.9 Auditing Approaches; Sample Audit Work-Planning Memo
4.10 Sample Audit Work Process Flow
4.11 Conducting a Risk-Based Information Systems Audit
4.12 Risk Assessment and Risk Management Strategy

Gain knowledge of the concept Unit 5: Business Continuity and Disaster Recovery Plan (6 Hrs.)
of Business Continuity and 5.1 Business Continuity and Disaster Recovery Process
Disaster Recovery Planning 5.2 Business Impact Analysis; Incident Response Plan
within the context of 5.3 Disaster Recovery Plan
Information System Audits, 5.4 Types of Disaster Recovery Plans
focusing on strategies to ensure 5.5 Emergency Preparedness Audit Checklist
organizational resilience and 5.6 Business Continuity Strategies
recovery in the event of 5.7 Business Resumption Plan Audit Checklist
disruptions. 5.8 Recovery Procedures Testing Checklist; Plan Maintenance
Checklist.

Apply the concept of VAPT and Unit 6: Security Testing and Cloud Computing Audit (5 Hrs.)
Emerging Concepts 6.1 Cybersecurity
6.2 Vulnerability Assessment and Penetration Testing (VAPT)
6.3 Security Testing Tools
6.4 Emerging Concepts in Information System Audit

5. Tutorial and Group Workshops (15 Hours)

The tutorial and group workshop should cover the following works:

SN Group Workshops
1. Information Security Gap Assessment through ISO 27001
2. Cybersecurity Maturity Assessment through NIST Cybersecurity Framework using CISA-CSET
or similar tools
3. Conduct Information System Audit and Reporting
4. Conducting Risk Assessment
5 Case Study: GRC Cybersecurity Engine
6. Evaluation system and Students’ Responsibilities

Internal Evaluation

The internal evaluation of a student may consist of assignments, attendance, internal assessment and
group workshop. The internal evaluation scheme for this course is as follows:

Internal Evaluation Weight Marks External Evaluation Marks


Theory

Attendance & Class Participation 10% 5


Assignments 10% 5
Semester-End 50
Presentations/Quizzes 10% 5 examination
Internal Assessment 50% 25
Group Workshops 20% 10
Total Internal 50
Full Marks: 50 + 50 = 100

Student Responsibilities:

Each student must secure at least 45% marks separately in internal assessment and practical evaluation
with 80% attendance in the class in order to appear in the Semester End Examination. Failing to get such
a score will be given NOT QUALIFIED (NQ) to appear for the Semester-End Examinations. Students are
advised to attend all the classes, formal exam, test, etc. and complete all the assignments within the
specified time period. Students are required to complete all the requirements defined for the completion
of the course.
7. Prescribed Books and References

References:

1. Hall, J. A. (2020). Information Technology Auditing and Assurance (5th ed.). Cengage Learning
2. Moeller, R. (2022). IT Audit, Control, and Security (3rd ed.). Wiley.
3. ISACA. (2024). CISA Review Manual. ISACA.
4. ISACA. (2022). COBIT 2019 Framework: Governance and Management of Enterprise IT. ISACA
5. Veena Hingarh and Arif Ahmed (2013), Understanding and Conducting Information Systems
Auditing, Wiley
6. Jack J. Champlain (2003), Auditing Information Systems, 2nd Edition, Wiley
7. Richard Cascarino (2007), Auditor’s Guide to Information Systems Auditing, Wiley
8. ISACA Journals
9. ISACA IT Audit Frameworks
10. NIST Special Publications
Elective : Big Data Technologies

Evaluation:
Theory Practical Total
Sessional 30 20 50
Final 50 - 50
Total 80 20 100

Course Description:
The growth of information systems has given rise to large amount of data which do not qualify as
traditional definition of data. This scenario has given us new possibilities but at same time pose serious
challenges. Such challenges lies in effective storage, analysis and search of such large set of data.
Fortunately, a number of technologies have been developed that answer such challenges. This course
introduces this scenario along with technologies and how they answer these challenges.

Objective of the Course:


To introduce student to current scenarios of big data and provide various facets of big data. It also
provides them with technologies playing key role in it and equips them with necessary knowledge to
use them for solving various big data problems in different domains.

Course Contents

1 Introduction to Big Data (8 Hours)


1.1 Big Data Overview
1.2 Background of Data Analytics
1.3 Role of Distributed System in Big Data
1.4 Role of Data Scientist
1.5 Current Trend in Big Data Analytics

2 Google File System (7 Hours)


2.1 Architecture
2.2 Availability
2.3 Fault tolerance
2.4 Optimization for large scale data
3 Map-Reduce Framework (10 Hours)
3.1 Basics of functional programming
3.1.1 Fundamentals of functional programming
3.1.2 Real world problems modeling in functional style
3.2 Map reduce fundamentals
3.3 Data flow (Architecture)
3.4 Real world problems
3.5 Scalability goal
3.6 Fault tolerance
3.7 Optimization and data locality
3.8 Parallel Efficiency of Map-Reduce
4 NoSQL (6 Hours)
4.1 Structured and Unstructured Data
4.2 Taxonomy of NoSQL Implementation
4.3 Discussion of basic architecture of Hbase, Cassandra and MongoDb

5 Searching and Indexing of Big Data (7 Hours)


5.1 Full text Indexing and Searching
5.2 Indexing with Lucene
5.3 Distributed Searching with elastic search
5.4
6 Case Study: Hadoop (7 Hours)
6.1 Introduction to Hadoop Environment
6.2 Data Flow
6.3 Hadoop I/O
6.4 Query languages for Hadoop
6.5 Hadoop and Amazon Cloud

Practical
Student will get opportunity to work in big data technologies using various dummy as well as real
world problems that will cover all the aspects discussed in course. It will help them gain practical
insights in knowing about problems faced and how to tackle them using knowledge of tools learned in
course.
1. HDFS: Setup a hdfs in a single node to multi node cluster, perform basic file system operation on it
using commands provided, monitor cluster performance
2. Map-Reduce: Write various MR programs dealing with different aspects of it as studied in course
3. Hbase: Setup of Hbase in single node and distributed mode, write program to write into hbase and
query it
4. Elastic Search: Setup elastic search in single mode and distributed mode, Define template, Write data
in it and finally query it
5. Final Assignment: A final assignment covering all aspect studied in order to demonstrate problem
solving capability of students in big data scenario.

References

1. Jeffrey Dean, Sanjay Ghemawat, MapReduce:Simplified Data Processing on Large Clusters


2. Sanjay Ghemawat, Howard Gobioff, and Shun-Tak Leung, The Google File System
3. Fay Chang, Jeffrey Dean, Sanjay Ghemawat, Wilson C. Hsieh, Deborah A. Wallach, Mike Burrows,
Tushar Chandra, Andrew Fikes, and Robert E. Gruber, Bigtable: A Distributed Storage System for
Structured Data
4. [Link]
5. [Link]
6. [Link]
7. Tom White, Hadoop: The Definitive Guide
8. Lars George, Hbase: The Definitive Guide
9. Jason Rutherglen, Ryan Tabora, Jack Krupansky, Lucene and Solr: The Definitive Guide
Oracle Course Detail for NCIT

Introduction (20 Hours including Practice)


Retrieve row and column data from tables with the SELECT statement

- Review the syntaxes for the basic SQL SELECT statements


- Use Arithmetic and Concatenation operators in SQL statements
- Save SQL statements to script files

Restricting and Sorting Data

- Limit rows using a selection


- Using the WHERE clause to retrieve specific rows
- Using the comparison conditions in the WHERE clause
- Use the LIKE condition to compare literal values
- List the logical conditions AND, OR, NOT
- Sort rows with the ORDER BY clause

Reporting Aggregated Data Using the Group Functions

- Use the group functions


- Utilize the DISTINCT keyword with the group functions
- Create groups of data with the GROUP BY clause
- Group data by more than one column
- Exclude groups of data with the HAVING clause

Using the SET Operators

- Use the UNION operator to return all rows from multiple tables and eliminate any duplicate
rows
- Use the UNION ALL operator to return all rows from multiple tables
- Describe the INTERSECT operator
- Explain the MINUS operator
- Use the MINUS operator

Manipulating Data

- Write INSERT statements to add rows to a table


- Copy rows from another table
- Create UPDATE statements to change data in a table
- Generate DELETE statements to remove rows from a table
- Save and discard changes to a table through transaction processing
- Show how read consistency works
- Describe the TRUNCATE statement

Using DDL Statements to Create and Manage Tables

- List the main database objects and describe the naming rules for database objects
- Display the basic syntax for creating a table
- Explain the different types of constraints
- Create a table with a sub query
- Describe the ALTER TABLE functionality
- Remove a table with the DROP statement and Rename a table

Controlling User Access

- System versus objects privileges


- Creating user sessions and granting system privileges
- Using roles to define user groups
- Creating and granting privileges to a role
- Granting and revoking object privileges
- Changing your password
- Using Database Links

Administration (20 Hours including Practice)

Installing the Oracle Database Software

- Installing the Oracle Database Software


- Install software with the Oracle Universal Installer (OUI)

Creating an Oracle Database

- Create a database with the Database Configuration Assistant (DBCA)

Managing the Oracle Instance

- Start and stop the Oracle database and components

Administering User Security

- Create and manage database user accounts


- Authenticate users
- Grant and revoke privileges
- Create and manage roles
Managing Schema Objects

- Create and modify tables


- Define constraints
- View the columns and contents of a table
- Create indexes, views and sequences

Managing Data and Concurrency

- Describe triggers and triggering events

Configuring the Oracle Network Environment

- Create additional listeners


- Create Net Service aliases

Back Up and Restoration

- Export and import Dump


Web Services and Applications

Credit: 3
Credit Hours: 45

Course Objectives:
1. To provide intermediate knowledge on Web Technology
2. To design and implement modern web APIs
3. Understand and implement the modern technologies of web.

Course Contents:

1. Ecosystems of Web Applications (5 hrs)


1.1. Basic elements of Web - HTML/CSS/Javascript
1.2. Anatomy of website/web-applications and Mobile Applications
1.3. Basics of IP and Networking
1.4. Hosting and Domain

2. Programming Technologies Basics (8 hrs)


2.1. Python as a programming language
2.2. Virtual Environments in Python
2.3. Flask - python framework
2.4. Database - Mysql and basics

3. Web Architectures (5 hrs)


3.1. 3-tier web architecture
3.2. Presentaion Layer and technologies
3.3. Application Layer and technologies
3.4. Database Layer and technologies
3.5. Modern (MVC) architecture

4. API Introduction (5 hrs)


4.1. Basics of API and its relation with the 3-tier architecture
4.2. How does API work with Examples
4.3. Need and features of API
4.4. Modern API integrations
4.5. Sample API based on Python/Flask
5. Restful Web Services (8 hrs)
5.1. What is REST?
5.2. HTTP Methods
5.3. HTTP Status Codes
5.4. Sample codebase to demonstrate REST and its advantage over traditional API concepts

6. Microservices (4 hrs)
6.1. What is Micro-services architecture?
6.2. Advantages/Dis-advantages
6.3. Communications in Microservices architecture
6.4. Demonstration of microservice architecture

7. API Testing (5 hrs)


7.1. Approaching API Testing
7.2. Tools for API Testing
7.3. Postman
7.4. API Clients

8. JSON vs XML (2 hrs)


8.1. What is JSON?
8.2. Usage of JSON
8.3. JSON over XML

9. Web Service Security ( 3 hrs)


9.1. Basics of Web Security
9.2. Authentication
9.3. Authorization
9.4. JWT Tokens

You might also like