MASTER OF SCIENCE INFORMATION TECHNOLOGY AUDIT (MIA)
| Module Code | Module Name | Description |
|---|---|---|
|
MIA501
|
Information Technology Audit and Control |
The module discusses how technology is constantly evolving and shaping today’s business environments. It also teaches students about the audit profession, with particular interest in IT auditing.Following the discussion of auditing, current trends and needs of IT auditing are described, as well as the various roles of an auditor in the IT field. The module also equips students with explanations of the complete audit process as well as the tools used.. Indicative content includes the audit lifecycle, from planning and risk assessment to the evaluation of general and application controls. Students will study the frameworks like COBIT, the use of tools like Computer-Assisted Audit Techniques (CAATs), and the reporting requirements for communicating audit findings to executive management and regulatory bodies. |
|
MIA502
|
Information Technology Governance and Management |
This module will introduce students to IT governance concepts, and the tools and techniques used in developing IT governance infrastructure. After completing the module, students are expected to building and monitor effective IT governance systems, monitor and measure enterprise management and board governance. This module examines how organizations align IT strategy with business goals through effective governance frameworks and management practices. Indicative content focuses on IT investment evaluation, resource management, and strategic alignment. Students will explore industry standards such as ITIL and ISO/IEC 38500, focusing on the roles of the Board and senior management in overseeing IT performance, compliance, and ethical technology use. |
|
MIA503 |
Forensics and Incident Response |
The module focuses on the procedures for identification, preservation, and extraction of electronic evidence, auditing and investigation of network and host system intrusions, analysis and documentation of information gathered, and preparation of expert testimonial evidence. The module will also provide hands-on experience on various forensic tools and resources for system administrators and information system security officers.This module also prepares auditors to participate in and evaluate the response to security breaches while maintaining the integrity of digital evidence. Indicative content covers the technical procedures for evidence preservation, chain of custody, and post-incident forensic analysis. Students will learn to audit an organization's Incident Response Plan (IRP), evaluate the effectiveness of containment strategies, and ensure that forensic investigations meet legal and regulatory requirements. |
|
MIA504 |
Information Warfare |
This module will address some of the unique and emerging policy, doctrine, strategy, and operational requirements of conducting cyber warfare in organisations at the nation-state level. It provides students with a unified battle-space perspective and enhances their ability to manage and develop operational systems and concepts in a manner that results in the integrated, controlled, and effective use of cyber assets in warfare. Indicative content includes the study of psychological operations, electronic warfare, and information operations within a global context. Students will analyze the defensive measures required to protect critical information infrastructure from state-sponsored attacks, propaganda, and strategic misinformation campaigns. |
|
MIA505 |
Big Data Analytics And Business Intelligence |
This Module will give students an advanced level of understanding of most recent advancements in Big Data and using insights, statistical models, visualization techniques for its effective application in Business intelligence. Business intelligence concepts will be discussed as well as their link with data analytics.. Indicative content involves the application of data mining, predictive modeling, and visualization techniques to identify fraud or operational inefficiencies. Students will learn to leverage Business Intelligence (BI) platforms to transform raw audit data into actionable reports that support evidence-based decision-making. |
|
MIA506 |
Cyber Threat Intelligence |
This module will give students an understanding of the myriad cyber threats and actor motivations. It equips students with the intelligence that they can use to guide organizations in accurately accessing threats, risks, and vulnerabilities, to minimize the potential for incidents and, when necessary, provide more thoughtful responses. This module teaches students how to collect, analyze, and apply information about existing and emerging threats to improve an organization's security posture. Indicative content covers the threat intelligence lifecycle, including the identification of threat actors, their tactics, techniques, and procedures (TTPs), and the use of indicator sharing platforms. Students will learn to integrate threat intelligence into risk management and audit planning to proactively address vulnerabilities. |
|
MIA507 |
Penetration Testing and Vulnerability Assessment |
The purpose of this module is to provide students with an in-depth understanding of the methodologies and techniques used for penetrating a machine using tools. The module also focuses on vulnerability assessment as well as the ethical issues involved. Indicative content includes the methodologies for vulnerability scanning, exploitation simulation, and the assessment of remediation efforts. Students will focus on evaluating the scope and effectiveness of penetration tests conducted by third parties and ensuring that findings are prioritized based on business risk. |
|
MIA508 |
Risk Assessment and Security Audit |
The purpose of this module is to provide students with an in-depth understanding of risk assessment while handling and processing information and implementing security in audit.The module integrates risk management principles with the technical execution of security audits. Indicative content covers qualitative and quantitative risk assessment methodologies, such as NIST SP 800-30. Students will learn to design audit programs that test the effectiveness of administrative, technical, and physical security controls, ensuring alignment with international standards like ISO 27001. |
|
MIA508 |
Cyberspace Operations and Design |
This module explores the architecture and design principles of secure cyberspace operations within complex environments. Indicative content includes network defense design, the implementation of "Zero Trust" architectures, and the operational planning of cyber activities. Students will analyze how system design choices impact the auditability and resilience of digital infrastructure against sophisticated persistent threats. |
|
MIA508 |
Research Methods |
This module serves as a fundamental building block in equipping students with the knowledge and competencies to conduct research in the computing field. Qualifying students have an appreciation of the research process and the reason for conducting research according to a specific research paradigm, to solve a problem. They determine appropriate sources to consult for a literature review. Students understand appropriate research strategies, data gathering and analysis techniques to obtain answers to the stated research problem. The module will cover the following; Problem identification, Objective formulation, Anatomy of a literature review, Writing a captivating abstract, Methodology, Results and discussion, conclusion, Research contributions. The module provides the academic tools necessary to conduct rigorous research in the field of IT audit and cybersecurity. Indicative content includes research design, data collection methods (both qualitative and quantitative), and statistical analysis. Students will learn to critically evaluate existing academic literature, formulate research hypotheses, and adhere to ethical standards in the conduct of their investigations. |
|
MIA560 |
Dissertation |
The dissertation is the final independent research project where students apply their cumulative knowledge to a specific IT audit or security problem. Indicative content involves the development of a comprehensive thesis, from the initial proposal and literature review to the final analysis and defense. Students are expected to contribute original insights or practical solutions to the field of Information Technology Audit.The research finding are expected to be published in peer reviewed journals or conference proceedings. |



