VSFS:B_BI Information Security - Course Information
B_BI Information Security
University of Finance and AdministrationSummer 2027
- Extent and Intensity
- 2/0/0. 6 credit(s). Type of Completion: zk (examination).
- Guaranteed by
- Ing. Renata Janošcová, Ph.D.
Department of Computer Science and Mathematics – Departments – University of Finance and Administration
Contact Person: Mgr. Petra Dovhunová - Prerequisites
- There are no prerequisites for this course.
- Course Enrolment Limitations
- The course is offered to students of any study field.
- Course objectives
- Learning outcomes of the course unit the aim of the subject is to teach students to master basic theory, legislative framework, norms and practical approaches to information protection.
- Learning outcomes
- After completing the course the student will be able:
- Explain solidly the basic definitions of information protection.
- Focus on the protection of personal data (GDPR), the Cyber Security Act, and the Privacy Act.
- Be an informed member of the team who will prepare the building of ISMS in the company.
- Syllabus
- Basics of Information Security - definitions of basic terms, why deal with security, how to deal with safety, security features, security mechanisms, security policies.
- Legislative framework - the classification of sensitive information, the Act on the Protection of Classified Information and Security,the Personal Data Protection (GDPR) , the Law on Electronic Communications, the Civil Code , the Law on Capital Market, the Law on Cyber Security, the Trust-Building Services Act for electronic Transactions.
- Standards in the field of information security - Family ISO 27k.
- Information Security Management System - Safety Management, ISMS, PDCA cycle, documentation.
- History and mathematical foundations of cryptography - basic definitions, history, classical ciphers, Shannon's theory of security ciphers.
- Complexity and primality in cryptology - the Turing machine, complexity classes, their prime properties, prime in cryptology .
- Modern symmetric ciphers - definition, construction elements of modern symmetric ciphers, linear feedback registers, substitution boxes (S- boxes), stream ciphers, block ciphers.
- Asymmetric cryptography - the definition, the use of asymmetric algorithms, list of algorithms related to NP problems, RSA, ElGamal, elliptic curve cryptography.
- PKI and digital signature - definition of PKI, PKI layer, definition and use hash algorithms, MD5, SHA-X class, the electronic signature.
- RNG and PKCS - distribution random number generators, advantages and disadvantages of each type, testing random sequences, RNG in cryptography, PKCS standards.
- Cryptographic protocols - the distribution of cryptographic protocols, Diffie - Helmann protocol , Rivest -Shamir protocol, Shamir protocol of distribution secret.
- Microsoft and cryptography - server operating systems, OS MS Windows workstation, MS Office, VeraCrypt.
- Literature
- required literature
- MENEZES, A.J., van OORSCHOT, P.C. and S. A. VANSTONE. Handbook of Applied Cryptography (eBook). CRC Press, 2018. https://doi.org/10.1201/. ISBN 9780429466335.
- SMEJKAL, Vladimír, Tomáš SOKOL a Jindřich KODL. Bezpečnost informačních systémů podle zákona o kybernetické bezpečnosti. Plzeň: Aleš Čeněk, 2019. ISBN 978-80-7380-765-8.
- OCHODKOVÁ, Eliška. Matematické základy kryptografických algoritmů. Ostrava: VŠB – Technická univerzita Ostrava, 2012. Dostupné z: http://mi21.vsb.cz
- ČESKO. Zákon č. 264/2025 Sb., o kybernetické bezpečnosti. In: Sbírka zákonů České republiky. 2025.
- ČSN EN ISO/IEC 27001:2023 (36 9797). Informační bezpečnost, kybernetická bezpečnost a ochrana soukromí – Systémy managementu informační bezpečnosti – Požadavky. Praha: Česká agentura pro standardizaci, 2023.
- ČSN EN ISO/IEC 27002:2023 (36 9798). Informační bezpečnost, kybernetická bezpečnost a ochrana soukromí – Opatření informační bezpečnosti. Praha: Česká agentura pro standardizaci, 2023.
- ČESKO. Zákon č. 412/2005 Sb., o ochraně utajovaných informací a o bezpečnostní způsobilosti. In: Sbírka zákonů České republiky. 2005.
- EVROPSKÝ PARLAMENT A RADA. Nařízení (EU) 2016/679 ze dne 27. dubna 2016 o ochraně fyzických osob v souvislosti se zpracováním osobních údajů a o volném pohybu těchto údajů (GDPR). In: Úřední věstník Evropské unie. 2016, L 119, s. 1–88.
- ČESKO. Zákon č. 127/2005 Sb., o elektronických komunikacích a o změně některých souvisejících zákonů (zákon o elektronických komunikacích). In: Sbírka zákonů České republiky. 2005.
- ČESKO. Zákon č. 89/2012 Sb., občanský zákoník. In: Sbírka zákonů České republiky. 2012.
- ČESKO. Zákon č. 256/2004 Sb., o podnikání na kapitálovém trhu. In: Sbírka zákonů České republiky. 2004.
- ČESKO. Zákon č. 297/2016 Sb., o službách vytvářejících důvěru pro elektronické transakce. In: Sbírka zákonů České republiky. 2016.
- ČESKO. Zákon č. 110/2019 Sb., o zpracování osobních údajů. In: Sbírka zákonů České republiky. 2019.
- recommended literature
- NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY. Advanced Encryption Standard (AES). Gaithersburg, MD: NIST, 2001, aktualizováno 2023. FIPS 197-upd1. Dostupné z: https://doi.org/10.6028/NIST.FIPS.197-upd1
- EVROPSKÝ PARLAMENT A RADA. Směrnice (EU) 2022/2555 o opatřeních k zajištění vysoké společné úrovně kybernetické bezpečnosti v Unii (NIS 2). In: Úřední věstník Evropské unie. 2022, L 333.
- EVROPSKÝ PARLAMENT A RADA. Nařízení (EU) 2022/2554 o digitální provozní odolnosti finančního sektoru (DORA). In: Úřední věstník Evropské unie. 2022, L 333.
- not specified
- ČESKO. Vyhláška č. 408/2025 Sb., o regulovaných službách. In: Sbírka zákonů České republiky. 2025.
- ČESKO. Vyhláška č. 409/2025 Sb., o bezpečnostních opatřeních poskytovatele regulované služby v režimu vyšších povinností. In: Sbírka zákonů České republiky. 2025.
- ČESKO. Vyhláška č. 410/2025 Sb., o bezpečnostních opatřeních poskytovatele regulované služby v režimu nižších povinností. In: Sbírka zákonů České republiky. 2025.
- ČESKO. Vyhláška č. 411/2025 Sb., o bezpečnostních úrovních informačních systémů veřejné správy. In: Sbírka zákonů České republiky. 2025.
- EVROPSKÝ PARLAMENT A RADA. Nařízení (EU) 2024/2847 o horizontálních kybernetických bezpečnostních požadavcích na produkty s digitálními prvky (Cyber Resilience Act). In: Úřední věstník Evropské unie. 2024.
- EVROPSKÝ PARLAMENT A RADA. Nařízení (EU) 2024/1689, kterým se stanoví harmonizovaná pravidla pro umělou inteligenci (AI Act). In: Úřední věstník Evropské unie. 2024.
- Teaching methods
- Lectures and seminars in full-time study; tutorials in part-time study; compulsory seminar participation is 50 % in full-time study; compulsory tutorial participation is 50 % in part-time study.
- Assessment methods
The course is concluded with a credit and an exam.
CREDIT: To obtain a credit, it is necessary to obtain at least 40% of points in the written test and at the same time have at least 50% participation in the B_BI exercise for both PS and KS students. In case of lower participation in the exercise, it is necessary to obtain at least 50% of points in the written credit test.
EXAM: Only a student who has previously obtained a credit is admitted to the exam. The exam consists of processing and presenting a selected topic, which will be determined by the teacher. The team will consist of 2 - 3 students. You will receive more detailed instructions from the teacher in the first lesson.
The overall assessment will depend on the number of points from the credit, taking into account the quality of processing and presenting the exam topic.
REPEATING students - the same conditions as full-time students.
ISP students - attendance is optional, but the need to select 2 exam topics, otherwise the same as full-time students.
I RECOMMEND ISP and REPEATING students to submit a request for placement in a schedule (seminar) group with a specific teacher according to the instructions from the study department.
6 credits: 150 - 180 hours of study load (teaching + self-study).- Language of instruction
- Czech
- Teacher's information
- https://is.vsfs.cz/go/zc1awp
The course website (above) is a LINK to the team (subject) in MS Teams (then select your teacher's channel, or the form of study - KS or PS).
It is necessary to install MS Teams in the form of an application on your notebook/PC. The presentation will take place in the form of sharing your screen. Prepare yourself technically (+ camera, sound).
CONTACTS for the teacher: guarantor Ing. Renata Janošcová, Ph.D, 37037@mail.vsfs.cz (only for personal matters, everything else should be handled in MS Teams).
CONSULTATIONS: information can be found on the teacher's personal pages in IS VŠFS (Teaching). https://is.vsfs.cz/auth/osoba/37037#vyuka
- Further comments (probably available only in Czech)
- The course can also be completed outside the examination period.
- Enrolment Statistics (recent)
- Permalink: https://is.vsfs.cz/course/vsfs/summer2027/B_BI