Ensimag Rubrique Formation 2022

Information Systems Security - 5MMSSI9

  • Number of hours

    • Lectures 24.0
    • Projects -
    • Tutorials 12.0
    • Internship -
    • Laboratory works -
    • Written tests -


    ECTS 3.0


  • Being able to understand the threats and vulnerabilities and manage a security policy
    • Operating Systems
    • networks infrastructures
    • Applications and software engineering
    • Protocols and security property
    • Business Processes
  • What actions to avoid / limit
    • Guide to good practice and usage
    • Security Policy for information systems / Audit
    • Methodology


Sebastien VIARDOT


The module is largely based on the assignments to be made, consisting of fault analysis, the responses needed to limit the impacts (anticipation and reaction), and propose experiments to implement them.

The topics covered in the framed sessions are :

  • Introduction to the course, legal warning, assignments presentation.
  • Lab : Docker and vagrant, and setting up a security challenge
  • Good and bad use of crypto
  • Authentication methods
    • Certificates PKI, Kerberos, oauth2, case, SSO
    • PKI Certificate Lab
  • Blockchain
  • Local vulnerability and good practices
    • identification (3 factors), solutions. Identity theft
    • media confidentiality - encryption / access
    • Access rights and best practices
    • Exploits and answers
    • Hardware flaw, illustration via meltdown and spectrum (if not otherwise processed)
    • Buffer overflow lab
  • Network failures and good practices
    • Snort Lab
  • WEB security
    • WEB security lab
  • Protocol verification
    • Protocol verification lab


Having taken the following courses (or equivalent) is recommended:

  • Operating System Design Project - Foundations
  • Operating system and concurrent programming
  • Security of systems and networks


Evaluation type:
Work to be done (alone or in pairs) on a vulnerability analysis and an experiment + Peer evaluation. A total of 2 works to be done and 6 peer reviews to be done.

No written examination in limited time in normal session, evaluation in continuous control.

Type of examination: Work equivalent to render individually on the analysis of a new vulnerability + written or oral following the number of students catching up.
Specific room:
Duration: 2h if it is a writing, 1h if it is an oral.
Authorized documents: none
Prohibited documents (eg books, all documents): all



The course exists in the following branches:

  • Curriculum - Embedded Systems & Connect. Devices - Semester 9
see the course schedule for 2020-2021

Additional Information

Course ID : 5MMSSI9
Course language(s): FR

The course is attached to the following structures:

You can find this course among all other courses.