Master of Management Studies (M.M.S) IT Governance Compliance and Cyber Laws Syllabus - Mumbai University 2026
This is the M.M.S. syllabus under NEP 2020, in force from the academic year 2025-26: Semesters I and II from the revised circular and Semesters III and IV from the new one, both approved by the Academic Council on 20 May 2025. The earlier choice-based syllabus is still set alongside it for repeating candidates, so check which scheme your exam form names before you revise.
Loading syllabus...
Syllabus for IT Governance, Compliance and Cyber Laws
Course objectives
- 1 To familiarize students with principles of IT governance, compliance standards, and cybersecurity regulations.
- 2 To equip students with practical skills in implementing governance frameworks such as COBIT and ISO standards.
- 3 To develop analytical capabilities for aligning IT governance with business strategy and legal compliance.
- 4 To foster understanding of Indian and global cyber laws, data privacy, and intellectual property rights.
- 5 To cultivate strategic insights into risk management, accountability, and ethical IT practices.
Course outcomes
- CO1: Explain the purpose and structure of IT Governance frameworks like COBIT and ITIL
- CO2: Analyze and compare different governance standards and compliance frameworks.
- CO3: Apply IT governance principles to organizational scenarios.
- CO4: Evaluate legal and regulatory compliance requirements, including SOX and IT Act.
- CO5: Interpret key components of cyber laws including data privacy, IPR, and cybersecurity.
- CO6: Develop IT governance and compliance strategies that align with cyber laws.
Unit 1 CO1, CO3 · 8 hours
Introduction to IT Governance and COBIT Framework- Need for IT Governance- COBIT as an umbrella framework- COBIT Domains and KPAs- Implementing COBIT- COBIT from an audit perspective
Unit 2 CO1, CO2 · 8 hours
Governance Frameworks and Standards- Importance of IT governance and compliance- Overview of standards: COBIT, ISO 27000, ITIL/ITSM- Comparison of frameworks
Unit 3 CO2, CO4 · 8 hours
Compliance Regulations and Acts- Indian IT Act- Sarbanes-Oxley (SOX)- Graham-Leach- Bliley Act (GLBA)- RBI & Banking regulations- Basel III (for banks)
Unit 4 CO2, CO3 · 8 hours
Cybersecurity Standards and Best Practices- BS 7799 / ISO 27001- ITIL/ITSM revisited- NIST Framework- Industry-specific regulations and guidelines
Unit 5 CO4, CO5, CO6 · 8 hours
Cyber Laws – Key Areas- Cybercrime Laws (Hacking, Identity Theft)- Data Protection and Privacy (GDPR, CCPA)- Intellectual Property Laws- Electronic Transaction Laws with case studies
Unit 6 CO4, CO5, CO6 · 8 hours
Cyber Laws – Important Global Regulations- GDPR (EU)- CCPA (California)- CFAA & DMCA (USA)- EU Cybersecurity Act- Compliance strategy development
Unit 7 CO4, CO5, CO6 · 12 hours
Emerging Trends in IT Governance, Compliance and Cyber Laws with related case studies
Textbooks
- 1 Enterprise Governance of Information Technology: Achieving Alignment and Value, Featuring COBIT 5 by Steven De Haes and Wim Van Grembergen. Springer, 2015.
- 2 Strategies for Information Technology Governance by Wim Van Grembergen. IGI Publishing, 2003
- 3 “COBIT 2019 Framework: Introduction and Methodology” ISACA, Core textbook for understanding COBIT Framework
- 4 “Information Security Governance: Guidance for Information Security Managers” by W. Krag Brotby, Auerbach Publications
- 5 “IT Governance: How Top Performers Manage IT Decision Rights for Superior Results” by Peter Weill & Jeanne W. Ross, Harvard Business Review Press
- 6 “Cyber Law: The Indian Perspective” by Pavan Duggal, Universal Law Publishing
- 7 “Information Technology Law and Practice” by Vakul Sharma, Universal Law Publishing
Reference Books
- 1 “The Law of Cyber Crimes and Information Technology Law” by S.V. Joga Rao, Wadhwa & Co.
- 2 “Managing Information Security” by John R. Vacca, Syngress
- 3 “The Complete Guide to IT Service Management” by Addie Schwartz, IT Governance Publishing
- 4 “Understanding SOX and Internal Controls for the IT Professional” by Chris Davis & Mike Schiller, Syngress
- 5 “GDPR: A Practical Guide” by Suzanne Dibble, Suzanne Dibble Publishing
Reproduced from the University of Mumbai syllabus for Master of Management Studies (Two Year), Semester III and IV, AC 20/05/2025, Item No. 7.11 (N), in force from the academic year 2025-26. Wording and unit numbering are as printed there. The PDF above is the syllabus's own page, unaltered.
The complete syllabus
This subject is cut from the University circular for its semester. Open a document here if you want the whole thing rather than a single subject.