Master of Management Studies (M.M.S) Information System Security and Audit Syllabus - Mumbai University 2026
This is the M.M.S. syllabus under NEP 2020, in force from the academic year 2025-26: Semesters I and II from the revised circular and Semesters III and IV from the new one, both approved by the Academic Council on 20 May 2025. The earlier choice-based syllabus is still set alongside it for repeating candidates, so check which scheme your exam form names before you revise.
Loading syllabus...
Syllabus for Information System Security and Audit
Course objectives
- 1 To introduce foundational concepts, standards, and frameworks in information system security and auditing.
- 2 To equip students with practical skills for identifying, assessing, and mitigating security threats.
- 3 To develop analytical capabilities in planning and conducting IT audits and compliance checks.
- 4 To foster understanding of security governance, risk assessment, and incident response planning.
- 5 To cultivate strategic insights into evolving cybersecurity threats, tools, and regulatory frameworks.
Course outcomes
- CO1: Identify the need for information security and audit, and classify organizational information assets.
- CO2: Explain systems audit concepts and apply knowledge of auditor roles and ERP integration.
- CO3: Analyse system maintenance processes, including data flow, access control, and confidentiality.
- CO4: Evaluate security threats, disaster recovery plans, and internal controls.
- CO5: Compare audit certifications and assess the impact of systems audit on organizational integrity.
- CO6: Design audit approaches using emerging technologies and evaluate their effectiveness.
Unit 1 CO1 · 10 hours
Introduction to Information Security and Audit Need and importance of Information Security in organizations, Role and significance of Information Audit, Identification and classification of Information Assets, Overview of Information Security Risks, Strategies for managing Information Security risks
Unit 2 CO2 · 12 hours
Systems Audit – Concepts and Practices Concept and objectives of Systems Audit, Emerging trends in Systems Audit, Time and cost effectiveness of audit processes, Competent authorities and legal framework, Roles and responsibilities of Systems Auditors viz Internal Systems Auditor and External Systems Auditor. Prerequisites and planning for Systems Audit, Role of ERP systems in enabling Systems Audit
Unit 3 CO3 · 10 hours
System and Infrastructure Maintenance Review of information flow: inputs, processing, validation, and outputs, Review and management of systems in the organization, Change and modification controls, Authorization and approval mechanisms, Maintenance and disposal processes, Master file review and update procedures, Logical vs physical access controls, ensuring confidentiality and data protection, Differentiating physical records vs system records
Unit 4 CO4, C05 · 10 hours
Security Administration and Operations Audit Types of information security threats, Physical threats, System-based threats. Disaster Recovery Planning (DRP) and Business Continuity, Information integrity and validation controls, Role of management in Information Security Operations, Ensuring secure and compliant information processing, Internal checks and controls within Information Systems, Auditing of system operations and administration
Unit 5 CO4, CO5 · 8 hours
Global and Indian Perspectives on Systems Audit Overview of global and Indian certifications in Systems Audit, CISA, DISA, ISO 27001, CISSP, CIA, etc. Institutions and organizations providing certifications, Linkages between traditional and systems audits, Adoption of systems audits across industries, Case studies: Successful audits and failure stories, the role of systems audit in improving transparency.
Unit 6 CO5, CO6 · 5 hours
Emerging Trends and Professional Opportunities Growing demand and skill gaps in systems auditing, Link between systems audit and fraud reduction, Use of advanced IT (AI, Blockchain, Cloud) in audits, Automation in audit and continuous auditing techniques, Future trends in Information Systems Security and Audit, Career pathways in Information Security and Auditing
Unit 7 CO4, CO5, CO6 · 5 hours
Emerging Trends in Information System Security and Audit with related case studies
Textbooks
- 1 Auditing in a Computerized Environment by Mohan Bhatia. Tata McGraw-Hill.
- 2 Contemporary Auditing by Kamal Gupta. Tata McGraw-Hill.
- 3 Analysis and Design of Information Systems by V. Rajaraman. Prentice Hall of India
Reproduced from the University of Mumbai syllabus for Master of Management Studies (Two Year), Semester III and IV, AC 20/05/2025, Item No. 7.11 (N), in force from the academic year 2025-26. Wording and unit numbering are as printed there. The PDF above is the syllabus's own page, unaltered.
The complete syllabus
This subject is cut from the University circular for its semester. Open a document here if you want the whole thing rather than a single subject.