Instructions for participants of the e-course Security and Privacy in the Digital Environment
| Site: | Loomen za stručna usavršavanja |
| Course: | Security and Privacy in the Digital Environment |
| Book: | Instructions for participants of the e-course Security and Privacy in the Digital Environment |
| Printed by: | Gost (anonimni korisnik) |
| Date: | Tuesday, 28 July 2026, 8:16 AM |
Table of contents
- 1. General information about e-course
- 2. How the Course Works
- 3. Course Structure
- 4. Technical Information About the System Used for the E‑Course
- 5. Minimum Technical Requirements for Participating in the E‑Course
- 6. What Will You Find in the System?
- 7. Participant Responsibilities
- 8. Contact Information
- 9. Code of Conduct for the E‑Course
- 10. Literature
1. General information about e-course
The e-course Security and Privacy in the Digital Environment provides a fundamental understanding of the protection of personal data, digital identities, and systems from unauthorised access, misuse, and harmful consequences. The aim of this training is to equip participants with the skills needed for responsible and secure use of digital technologies through an understanding of the core principles of security and privacy in the digital environment. Participants will gain knowledge of technical and organisational measures for protecting personal data, digital identities, and information systems, as well as of the legislative framework governing the collection, processing, and sharing of data. The course emphasises the development of competencies for risk recognition, the application of security tools, and achieving a balance between user experience, privacy protection, and the lawful use of digital technologies.
Number of ECTS credits: 3
Participants: employees of higher education institutions in leadership positions
Total module duration: 75 hours
E-course learning outcomes:
- identify possible approaches to managing, protecting, and sharing digital resources and materials;
- recognise potential security and privacy risks associated with commonly used educational digital tools and platforms;
- evaluate digital educational resources based on their compliance with recognised security and privacy standards;
- relate security and privacy in the digital environment to their impact on student learning.
2. How the Course Works
The e‑course consists of nine units that build on one another both theoretically and practically. By completing individual and group assignments, participants deepen their understanding throughout the course. Activities include watching videos, analysing prepared materials in Loomen and materials provided through links, participating in forums, writing and submitting essays, and completing quizzes and games.
Some tasks in the e‑course are designed to be completed individually, while others may be done individually or in pairs. For tasks where the mode of work can be chosen (individually or in pairs), working in pairs is recommended throughout the entire course. Collaboration with other participants will be possible through planned activities such as forums and discussions. The instructor will inform you during the course about the detailed schedule for working on the topics.
3. Course Structure
The e‑course consists of nine thematic units. The following table shows the percentage by which each of the nine units contributes to each learning outcome.
|
|
Identify possible approaches to managing, protecting, and sharing digital resources and materials |
Recognise potential security and privacy risks associated with commonly used educational digital tools and platforms |
Evaluate digital educational resources based on their compliance with recognised security and privacy standards |
Relate security and privacy in the digital environment to their impact on student learning |
|
Threats and Risks to Digital Identity and Personal Data |
25 % |
|||
|
Cybersecurity Risks in Education – Case Studies |
20 % |
25 % |
20 % |
|
|
Digital Identity Management – Privacy Protection Strategies and Digital Footprints |
25% |
25% |
||
|
Best Practices in Digital Identity Management |
25 % |
|||
|
Management and Protection of Digital Resources and Materials |
25 % |
|||
|
Evaluation of Digital Resources – Criteria for Assessing the Security of Digital Tools and Platforms |
20 % |
|||
|
Compliance with Copyright, Data Protection, and Cybersecurity Laws and Regulations |
30 % |
35 % |
35 % |
|
|
Students’ Digital Literacy and Privacy |
40 % |
|||
|
Data Storage and Sharing in Education – Recommendations and Tools |
25 % |
25 % |
Unit 1: Threats and Risks to Digital Identity and Personal Data
In theoretical terms, this unit provides the fundamental concepts related to different types of cyber risks and threats to personal data, and the basics of prevention and risk management concerning personal data.
In practical terms, within this unit, participants are expected to analyse examples of personal data misuse and examine the consequences of compromised digital identity.
Unit 2: Cybersecurity Risks in Education
This topic helps participants understand cybersecurity threats in the education sector through examples of real attacks and vulnerabilities. They become familiar with the most common types of attacks, protection measures, and the consequences of security incidents. Special attention is given to the challenges of data protection in educational institutions and compliance with regulations such as the GDPR.
In practical terms, the topic helps participants develop skills in identifying security risks, analysing incidents, and developing preventive measures. Through a practical assignment, and with the support of the designated responsible person in their institution, they can assess the security policy and configuration within their own organisation.
Unit 3: Digital Identity Management – Strategies for Privacy Protection and Digital Footprints
In theoretical terms, this unit introduces the fundamentals of digital identity, its different types, how digital footprints are formed, and the threats and risks present in the digital environment. Participants will also become familiar with the legal frameworks for privacy protection and safety on social networks.
In practical terms, participants will explore security tools, examine real‑world examples, take part in discussions, and write an essay on the impact of digital traces on privacy and how they can be managed.
Unit 4: Best Practices in Digital Identity Management
In theoretical terms, participants will learn the fundamentals of authentication, authorisation, and best practices in digital identity management by studying relevant sources.
In practical terms, they will analyse an IAM tool to gain a better understanding of identity lifecycle management and take part in a forum discussion on access management and auditing (Access Governance).
Unit 5: Management and Protection of Digital Resources and Materials
In theoretical terms, participants will learn about the different types of digital resources and materials, how to protect them, and the legal and ethical aspects of sharing content.
In practical terms, they will explore security tools such as PGP and OnlyOffice, test their features for protecting digital materials, and take part in a forum discussion on ethics and the legal framework of protection.
Unit 6: Evaluation of Digital Resources – Criteria for Assessing the Security of Digital Tools and Platforms
In theoretical terms, participants will learn the criteria for evaluating the security of digital tools and platforms, become familiar with the ISO 27000 series of standards, and understand procedures for managing security incidents.
In practical terms, they will independently analyse the security aspects of their institution’s IT infrastructure, participate in a discussion, and—with the support of the responsible person in their organisation—prepare an assessment of their institution’s compliance with the ISO 27001 standard.
Unit 7: Compliance with Copyright, Data Protection, and Cybersecurity Laws
In theoretical terms, participants will learn the basic legal frameworks related to copyright, personal data protection, and cybersecurity.
In practical terms, they will independently study the relevant literature, write an essay on a selected topic, and participate in a forum discussion on user rights in the field of data protection.
Unit 8: Students’ Digital Literacy and Privacy
In theoretical terms, participants will gain knowledge about the threats and risks to students’ digital security, as well as the technological challenges and innovations related to privacy protection in education.
In practical terms, they will work on developing a security‑aware culture through exercises, analyse the challenges of online learning, and participate in a forum discussion on privacy protection in the digital educational environment.
Unit 9: Data Storage and Sharing in Education – Recommendations and Tools
In theoretical terms, participants will learn about tools and recommendations for storing and sharing data in education, including mobile device security and digital ethics.
In practical terms, they will explore and use data‑management tools and take part in a forum discussion on data privacy and examples of good practice.

Figure 1: Overview of Summative Assessment
4. Technical Information About the System Used for the E‑Course
This e‑course is implemented in the Loomen system, which is based on the open‑source Moodle platform. The course homepage is organised according to the course structure, with links directing participants to activities and resources in line with the course design.
The e‑course can be accessed from any internet‑connected computer, as well as from smartphones and tablets. It opens correctly in all major web browsers (Firefox, Opera, Chrome, Edge…) and is also available through a mobile application, although the app does not always function optimally.
Faster navigation through the course is possible using the menu on the left side, while the right side provides an overview of upcoming activities, highlighted announcements, and course progress.
The Loomen system is intuitive, and in case of any difficulties, participants should contact the instructor.
5. Minimum Technical Requirements for Participating in the E‑Course
Types of Content in the E‑Course
Educational multimedia materials (primarily text‑based), such as lessons and pages, are available in the Loomen system and can be opened directly in a web browser. All materials can also be downloaded in PDF format. For this reason, users need to have a PDF reader installed. If using browsers such as Firefox or Chrome, a separate PDF reader is not required because PDFs can be opened directly in the browser.
Video lessons are originally hosted on CARNET’s multimedia portal Meduza and are integrated into Loomen pages, allowing access without leaving the Loomen system. To watch video lessons, an internet connection of at least 2 Mbit/s is required. In addition, headphones or speakers are needed.
The practical part of the assignment is completed using a spreadsheet application, so participants must have an appropriate tool installed, preferably MS Excel.
Assessment activities in the e‑course are supported by the built‑in functionalities of the Loomen system, and no additional technical requirements are needed. Quizzes open entirely within the web browser, and no further technical prerequisites are required.
Synchronous activities in the course are conducted using the Big Blue Button platform, which is integrated into Loomen. The technical requirements for participating in synchronous sessions include a microphone, headphones, and an internet connection (preferably 5 Mbit/s or higher).
6. What Will You Find in the System?
Within the thematic blocks, you will find:
- Video lesson – concise educational videos that deliver key information on a specific topic clearly and efficiently in just a few minutes
- Book – content structured into chapters for step‑by‑step learning, which you can read like a digital textbook
- Quiz – short knowledge checks related to the material you have read; quizzes may include multiple‑choice questions, true/false items, and short‑answer questions
- Game – interactive activities for reviewing content in an engaging way (e.g., matching terms)
- Assignments or forums – you will be able to submit your work (essay, Excel file) or participate in discussions with peers and mentors
7. Participant Responsibilities
Participants are encouraged to engage in as many activities as possible, including reviewing and analysing video lessons and educational materials, completing practical tasks, writing essays, taking quizzes, and more. Throughout the implementation of the e‑course, it is possible to collect points—up to a maximum of 46. The following table provides an overview of the mandatory course activities by topic, mode of completion, and the number of points that can be earned. The course is considered successfully completed if at least 25 points are achieved in total, with at least one third of the points earned in each assessed activity.
|
Topic |
Mandatory Activity or Activity for Points |
Individual (I) / |
Points |
|
Threats and Risks to Digital Identity and Personal Data |
Types of Cybersecurity Risks and Threats to Personal Data |
I |
0 |
|
Quiz – Examples of Misuse and the Effects of Compromised Digital Identity |
I/P |
4 |
|
|
Essay – Studying Literature on Misuse Examples and the Effects of Compromised Digital Identity |
I |
6 |
|
|
Quiz |
I |
4 |
|
|
Cybersecurity Risks in Education – Case Studies |
Cybersecurity Incidents and Strategies for Preventing Future Security Incidents – Video Lesson |
I/P |
0 |
|
Independent Study of Data Protection Challenges in the Education Sector |
I/P |
0 |
|
|
Essay – Challenges in Data Protection in the Education Sector |
I |
6 |
|
|
Digital Identity Management – Strategies for Privacy Protection and Digital Footprints |
Basic Concepts and Types of Digital Identities – Video Lesson |
I |
0 |
|
Study of External Sources on the Use of Security Tools and Strategies for Privacy Protection in the Digital Environment |
I/P |
0 |
|
|
Discussion on Threats and Risks in Digital Identity Management – Forum |
I/P |
0 |
|
|
Essay – The Impact of Digital Traces on Privacy and Managing Digital Footprints |
I |
0 |
|
|
Best Practices in Digital Identity Management |
Authentication and Authorisation – Video Lesson |
I |
0 |
|
Study of Sources on Authentication and Authorisation |
I |
0 |
|
|
Essay – Recommended Authentication and Authorisation System Today |
I |
0 |
|
|
Discussion on Access Management and Auditing (Access Governance) – Forum |
I/P |
0 |
|
|
Management and Protection of Digital Resources and Materials |
Study of External Sources on Types of Digital Resources and Materials – Video Lesson |
I |
0 |
|
Quiz |
I |
4 |
|
|
Evaluation of Digital Resources – Criteria for Assessing the Security of Digital Tools and Platforms |
Independent Study of Criteria for Assessing the Security of Digital Tools and Platforms |
I |
0 |
|
Independent Study of Digital Teaching Materials |
I |
0 |
|
|
Preparation of an ISO 27001 Compliance Assessment for the Participant’s Institution Using the Provided Excel Template |
I |
0 |
|
|
Compliance with Copyright, Data Protection, and Cybersecurity Regulations |
Review of a Video Lesson on Legal Regulations, Copyright, Personal Data Protection, and Cybersecurity |
I |
0 |
|
Essay – Legislative Solutions |
I |
6 |
|
|
Quiz |
I |
4 |
|
|
Students’ Digital Literacy and Privacy |
Independent Study of Prepared Literature on Threats and Risks to Digital Security in the Educational Environment |
I/P |
0 |
|
Quiz – Exercises on Building a Security Culture |
I/P |
4 |
|
|
Assignment Submission – Building a Security Culture in Educational Institutions |
I/P |
0 |
|
|
Quiz |
I |
4 |
|
|
Data Storage and Sharing in Education – Recommendations and Tools |
Independent Study of Literature on Data‑Management Tools and Platforms |
I/P |
0 |
|
Secure Data Storage and Best Practices for Data Sharing |
I/P |
0 |
|
|
Data Security in Mobile Device Environments |
I/P |
0 |
|
|
Discussion on Data Privacy and Digital Ethics with Examples of Good Practice – Forum |
I |
0 |
|
|
Quiz |
I |
4 |
|
|
Total |
46 |
||
8. Contact Information
For all content‑related questions and questions about participating in the e‑course, please contact your instructor. For technical issues, reach out via email at x@carnet.hr or by phone at 01 xxxxxxx.
9. Code of Conduct for the E‑Course
To ensure effective collaboration, we have defined a set of rules for appropriate behavior in the e‑course.
-
Respect other participants as if they were in the same room with you. Maintain a culture of appreciation and constructive dialogue. Behind every username is a real person—kindness and empathy are key to a positive learning environment.
-
Use professional and clear language. Aim for grammatically correct writing, avoid using all caps (which may be interpreted as shouting), and express your thoughts clearly. Inappropriate or offensive messages are not acceptable.
-
Stay on topic and be concise. Your comments, responses, and messages should relate to the subject and be structured in a way that others can easily understand. Clear and focused communication benefits both you and your peers.
-
Participate actively and on time. Your engagement contributes to the quality of shared learning. Check announcements regularly, complete tasks within deadlines, and take part in discussions.
-
Protect privacy and confidentiality. Do not share other participants’ personal data without their explicit consent. Be cautious when sharing your own information in public course spaces.
-
Do not post promotional or unsolicited content. The course is not a place for advertising, chain messages, or political messaging. The focus should remain on course content and mutual learning.
-
Express disagreement constructively. Direct criticism toward the content or idea, not the person. If you disagree, support your viewpoint with arguments while respecting different perspectives.
-
Use appropriate communication channels. For technical or organisational questions, use the designated forums or contact course mentors through official channels. Informal communication is welcome in the spaces intended for it, as long as basic courtesy is maintained.
-
Prepare for participation in virtual meetings. If the course includes video sessions, it is recommended to use your camera (when possible), stay in a quiet environment, and speak only when you have a comment or question. Respect others’ time and avoid disrupting the session.
-
Act in accordance with ethical and legal standards. Respect copyright, institutional policies, and applicable laws. Unauthorised use of materials, plagiarism, or sharing confidential information is not permitted.

This e‑course is made available under the Creative Commons Attribution–NonCommercial–ShareAlike 4.0 International license. When using any part of the material, we recommend attributing the work in the following way:
Žagar M. (2025). Security and Privacy in the Digital Environment. 1st edition of the CARNET e‑course. Retrieved from the link.
Why these rules? The aim is to ensure a high‑quality, inclusive, and professional learning environment in which everyone feels comfortable.
What if the rules are violated? If participants do not follow the rules, course facilitators may issue a warning and, in more serious cases, take further steps in accordance with institutional policies.
Who is responsible? All course participants share responsibility for maintaining a positive and professional atmosphere.
10. Literature
The list of literature used in the preparation of the course is provided in the Course Literature activity.
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight