ITOP 2110: Cyber Defence and Operations
Effective date
January 2027
School
Continuing Studies
Description
Students will learn how to monitor, defend, and respond to security events in modern IT environments. In this course, students will analyze security telemetry, triage alerts using structured playbooks, and correlate data from multiple sources to identify potential threats. Students will also practice containment and remediation techniques, apply industry‑informed frameworks, and produce clear incident documentation.
Year of study
2nd Year Post-secondary
Course Learning Outcomes
Upon successful completion of this course, students will be able to:
- Configure and validate firewall components, policies and security features, developing basic detection rules or queries to improve threat identification and reduce false positives.
- Identify core SIEM components, including security telemetry, documenting data sources and schemas and customizing dashboards for effective security monitoring.
- Triage security alerts using SOC tools and playbooks, distinguishing true positives from false positives and documenting escalation decisions.
- Correlate security telemetry from multiple sources, such as open-source security monitoring agents and intrusion detection systems, to build incident timelines and identify key indicators of compromise.
- Apply containment and remediation strategies to mitigate security incidents, verifying effectiveness through follow-up validation.
- Map incident activities to recognized cybersecurity frameworks (e.g. MITRE ATT&CK, NIST CSF, CIS Controls), and document findings in case notes.
- Produce a comprehensive incident report summarizing technical details, business impact, and lessons learnt.
- Conduct a post-incident review and recommend improvements to processes, controls, or technologies based on findings.
- Demonstrate structured use of incident response playbooks across all phases of the response lifecycle.
Prior Learning Assessment & Recognition (PLAR)
PLAR is assessed through one or more of the following methods: student portfolio/products, demonstration/simulation, project-based asessment, or through another assessment method that is aligned with the course learning outcomes.
Hours
Lecture, Online, Seminar, Tutorial: 48
Clinical, Lab, Rehearsal, Shop, Kitchen, Simulation, Studio: 24
Total Hours: 72
Instructional Strategies
Instructional strategies may include:
Knowledge checks
Lectures
Hands-on lab activities
Scenario-based activities
Demonstrations
Problem-based exercises
Discussion
Reflection
Grading System
Letter Grade (A-F)
Evaluation Plan
|
Type
|
Percentage
|
Assessment activity
|
|
Project
|
45-60
|
Project involving multiple SOC components.
|
|
Assignments
|
40-55
|
Multiple hands-on lab exercises and/or assignments
|
Course topics
- Firewall Configuration & Policy Management
SIEM Architecture & Data Collection
Alert Triage & False Positive Reduction
Threat Detection & Correlation Analysis
Incident Containment & Remediation
Incident Documentation & Framework Mapping
Incident Response Lifecycle & Post-Incident Review
Notes:
- Course contents and descriptions, offerings and schedules are subject to change without notice.
- Students are required to follow all College policies including ones that govern their educational experience at VCC. Policies are available on the VCC website at:
https://www.vcc.ca/about/governance--policies/policies/.
- To find out if there are existing transfer agreements for this course, visit the BC Transfer Guide at https://www.bctransferguide.ca.