Jason Hartley is lecturer in criminology at Griffith University in Brisbane, Australia. He is a former police officer with 23 years of experience, and has trained personnel for deployment in Timor Leste, the Solomon Islands, Iraq and Afghanistan. Jason specializes in, and has published on engagement with Muslim communities, Indigenous Polynesian approaches to rehabilitation and reducing recidivism, and Asian Organised Crime. Jason also completed a community internship in Hebron on the West Bank.
ITC402 Cybersecurity Management
This unit introduces the managerial, governance and cultural dimensions of cybersecurity. Students learn to align security strategy with organisational objectives, craft policy, develop risk-management processes and cultivate a positive security culture. Using frameworks such as NIST CSF, ISO 27001 and ASD Essential Eight, the unit emphasises program planning, metrics, stakeholder communication and change leadership—skills essential for emerging CISOs and security managers.
RELEVANT COURSES
* Core unit
CREDIT POINTS
10
STUDY MODES
On campus, online, hybrid
PREREQUISITE OR CO-REQUISITE
Nil
UNIT LEARNING OUTCOMES
- Critically analyse organisational contexts to determine cybersecurity governance and compliance requirements
- Evaluate and apply recognised frameworks to develop policy and risk-treatment strategies
- Design a multi-year cybersecurity-program roadmap encompassing awareness, incident readiness and vendor-risk management
- Develop metrics, KPIs and dashboards that communicate security posture, ROI and risk appetite to executive stakeholders
- Reflect on and articulate leadership approaches that foster security culture and drive organisational change
CONTENT
- Cybersecurity management fundamentals and governance models
- Standards & frameworks: NIST CSF, ISO 27001, ASD Essential Eight
- Roles, responsibilities and policy lifecycle
- Risk management process and risk-appetite statements
- Security‐awareness programmes and behaviour-change techniques
- Vendor & supply-chain security governance
- Incident-readiness integration with BC/DR
- Metrics, OKRs an dashboard design (Power BI lab)
- Budgeting, business cases & resource planning
- Audit, compliance an assurance
- Leadership, change management & stakeholder communication
- Emerging trends: SASE, zero-trust governance, AI risk
ASSESSMENT METHODS
- Governance Gap-Analysis Report – 20%
- Group Cybersecurity Program Roadmap and Pitch – 30%
- Security-Posture Dashboard and Reflection – 50%
PRESCRIBED READINGS
Check with the lecturer each semester before purchasing any texts












