1/294
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
CIA Triad
The three core security goals: Confidentiality (only authorized access), Integrity (data stays accurate and unaltered), Availability (systems and data accessible when needed).
Confidentiality
Ensures information is safe from accidental or intentional disclosure; only authorized people/processes can access sensitive data.
Integrity
Ensures data is complete, accurate, and not altered or corrupted, accidentally or intentionally.
Availability
Ensures authorized users can access information, systems, and resources whenever they need them.
Opposite of confidentiality, integrity, and availability
Confidentiality = Disclosure; Integrity = Alteration; Availability = Destruction.
Controls that support confidentiality
Encryption and strong passwords.
Controls that support integrity
Hashing, digital signatures, and encryption (which keeps intercepted data from being altered meaningfully).
Controls that support availability
Backups and redundant systems.
Common threats to confidentiality
Data breaches, man-in-the-middle attacks, phishing, insider threats, malware, and spyware.
Common threats to integrity
Man-in-the-middle attacks, SQL injection, ransomware, malicious code, and viruses.
Common threats to availability
DDoS attacks, ransomware, hardware failure, natural disasters, and insider threats or faulty updates (e.g., the CrowdStrike outage).
Why the CIA Triad needs balance
Focusing on only one pillar (e.g., confidentiality) leaves systems exposed to data manipulation or outages. A holistic approach across all three is required.
Which CIA pillars do banking systems prioritize?
Confidentiality and Integrity (gaming servers, by contrast, prioritize Availability).
Vulnerability
A flaw, weakness, or security hole in a system, component, or procedure (e.g., buffer overflow, weak password policy, unencrypted Wi-Fi).
Threat
Any entity, force, or agent (person, code, or nature) capable of exploiting a vulnerability to compromise C, I, and/or A.
Examples of threats
Hackers, nation-state actors, terrorists, worms, viruses, phishing emails, ransomware, floods, windstorms, solar storms.
Risk
The likelihood that assets will be compromised, causing loss of C, I, and/or A; the cost of a mission-impacting event weighted by its probability.
Risk formula
Risk = Vulnerability x Threat x Impact
When is risk zero?
When either the vulnerability or the threat is absent. Risk requires both to exist at the same time.
Example of zero risk: no password
A computer with no password (vulnerability) but no threat actors able to exploit it has risk = 0.
Example of zero risk: hurricane
A Florida hurricane (threat) cannot harm servers located in Wyoming (no exposure/vulnerability), so risk = 0.
Realized risk
Occurs when a threat actor or event successfully exploits a vulnerability and impacts the confidentiality, integrity, or availability of an asset.
Ultimate goal of cybersecurity
Reduce risk to an acceptable level by applying controls and countermeasures.
Primary mission of threat actors
Steal money or steal data (which is converted into money) by compromising C, I, or A.
Countermeasure (control)
A tool or technique applied to reduce risk, enabling greater mission capability and system reliability.
Protect (countermeasure function)
Preventative measures that block unauthorized actions and security incidents.
Detect (countermeasure function)
Mechanisms that identify when a breach or adverse event occurs or when an attacker bypasses defenses (e.g., IDS).
React (countermeasure function)
Responsive actions that handle adverse events quickly to minimize mission impact.
Physical controls
Tangible mechanisms that prevent physical access: gates, fences, locks.
Logical (technical) controls
Technology/software mechanisms protecting digital systems: firewalls, OS updates, software patches.
Administrative controls
Policy-driven and managerial controls: security policies and user security training.
NIST SP 800-53
A comprehensive catalog of security and privacy controls published by the National Institute of Standards and Technology.
Defense in depth
Layering multiple security measures at different levels (e.g., door locks + network firewalls + security policies) to protect critical assets.
How controls relate to risk
Controls and countermeasures act on vulnerabilities and threats to decrease total risk to C, I, and A.
People, Process, Technology
The triad of effective security: People (training, awareness, culture), Process (policies, governance, procedures), Technology (firewalls, access controls, monitoring tools).
Script kiddie
An inexperienced attacker who uses existing automated scripts or tools.
Hacktivist
An attacker motivated by political, ideological, or social agendas.
Organized crime (threat actor)
Structured groups seeking financial gain through cyber attacks.
Nation-state / APT
State-sponsored groups with high sophistication, large resources, and long-term targets.
Insider threat
An employee, contractor, or trusted person who misuses authorized access.
Competitor (threat actor)
A corporate entity trying to gain illegal commercial advantage or intelligence.
Advanced Persistent Threat (APT)
A sophisticated, well-resourced, long-term attacker, typically state-sponsored.
White hat hacker
An ethical security professional who finds and fixes vulnerabilities with the system owner's permission.
Black hat hacker
A hacker who breaks into systems illegally with malicious intent (financial gain, data theft, disruption).
Grey hat hacker
A hacker who may break laws or ethical norms but usually without malicious intent.
Purple hat hacker
A professional who combines offensive (red team) and defensive (blue team) skills to strengthen security.
Social engineering
Manipulating people into giving up access or information by exploiting human psychology instead of technical vulnerabilities.
Phishing
Broad fraudulent messages designed to trick users into revealing credentials or information.
Spear phishing
Targeted phishing aimed at specific individuals or organizations.
Vishing
Voice-based phishing over phone or audio channels.
Dumpster diving
Searching trash for discarded paperwork that contains credentials or sensitive information.
Shoulder surfing
Directly observing someone entering credentials on a keyboard or screen.
Denial of Service (DoS)
An attack that overwhelms a single target (one endpoint) so legitimate users cannot access it.
Distributed Denial of Service (DDoS)
A DoS attack launched from many sources at once, flooding a network or service with traffic to knock it offline.
Man-in-the-middle (MITM) attack
An attacker secretly sits between two communicating parties to intercept and possibly alter their communication.
Buffer overflow
A software vulnerability where data exceeds a memory buffer's size, letting attackers corrupt memory or run malicious code.
Replay attack
An attacker intercepts a legitimate communication and resends it to trick the receiver into performing unauthorized actions.
Evil twin
A fraudulent Wi-Fi access point that mimics a legitimate network to intercept users' sensitive information.
Rogue access point
An unauthorized wireless device connected to a network, enabling data interception, malware distribution, and MITM attacks.
Birthday attack
A cryptographic attack exploiting hash-collision probability to find two different inputs that produce the same hash.
Known plaintext / ciphertext attack
The attacker has both plaintext and its matching ciphertext and tries to deduce the key or algorithm.
Rainbow table
A precomputed database mapping plaintext passwords to hash values, used to reverse hashes quickly without brute force. Salting defeats it.
Brute force attack
Systematically guessing passwords, usernames, or keys by trial and error, often with automated tools.
Ransomware
Malware that encrypts a victim's files and demands payment for the decryption key.
Ransomware-as-a-Service (RaaS)
A commercialized criminal model where ransomware platforms are rented (often via dark web subscriptions) to independent affiliates.
Botnet
A network of hijacked devices (often unsecured IoT) controlled by an attacker, e.g., the Mirai botnet.
Why unsecured IoT devices are dangerous
They can be hijacked to build botnets or used as lateral-movement pivot points into secure enterprise networks.
Deepfake
Synthetic video, audio, or images made with deep learning, used for social engineering, fraud, or disinformation.
AI-driven attacks
Attacks using AI for automated exploitation, advanced evasion, and intelligence gathering.
Quantum computing risk
Powerful quantum computers could break today's public-key (asymmetric) encryption, driving research into post-quantum cryptography (PQC).
Blockchain
A distributed ledger that records transactions across many computers so data is secure, transparent, and immutable; underpins cryptocurrencies like Bitcoin.
Stuxnet
A computer worm discovered around 2010 that marked a shift toward targeted, state-level cyber operations against specific infrastructure.
Why attackers hide MAC and IP addresses
Addresses are identifiers for a device; attackers can use them to locate and target you, so attackers themselves mask identity with tools like VPNs.
Internet Protocol (IP)
The networking protocol that provides addressing so data packets reach the correct destination.
Network protocol
A standardized set of rules governing how data is transferred across networks.
Evolution of threat actors: lone hackers
1980s-1990s: curiosity-driven individuals using phreaking and basic remote exploitation.
Evolution of threat actors: cybercrime rings
2000s: financially motivated syndicates running botnets, spam, identity theft, and carding forums.
Evolution of threat actors: nation-states
2010s: well-funded APTs pursuing espionage, military advantage, and infrastructure sabotage with zero-day exploits.
Evolution of threat actors: RaaS era
Present: commercialized extortion with modular ransomware platforms rented to affiliates.
NIST definition of cybersecurity
The ability to protect or defend the use of cyberspace from cyber attacks.
Practical definition of cybersecurity
Protecting systems, networks, and data from digital attacks, unauthorized access, damage, or disruption (also called IT security or electronic information security).
Three core system security questions
What are the cyber components? What are the threats and vulnerabilities? How can risk be reduced by design through engineering controls?
Information security
Protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.
Cybersecurity vs. cybersecurity engineering
Cybersecurity is the broad governance/risk/policy/human-factors discipline; cybersecurity engineering is the technical discipline that designs, builds, and configures security controls.
Cybersecurity engineering vs. information security
Engineering is hands-on and technical (scans, pen tests, firewalls, IDS, EDR); information security is strategic and governance-oriented (policies, compliance, audits, incident business impact).
Cybersecurity engineering 4-stage lifecycle
1) Design, 2) Build and Test, 3) Operate and Defend, 4) Improve.
Cybersecurity analyst
Monitors security telemetry and network feeds to detect, analyze, triage, and prevent threats.
Cybersecurity engineer
Architects and monitors critical systems, writes patches, and builds technical countermeasures.
Penetration tester
An ethical hacker who uses offensive tools to legally breach defenses and uncover exploitable vulnerabilities.
Network engineer
Deploys network hardware, configures firewalls, monitors traffic anomalies, and updates infrastructure.
Cloud security engineer
Designs, deploys, and manages security controls for public, private, or hybrid cloud environments.
Cyber incident responder / forensics specialist
Performs triage, forensics, containment, log analysis, and root-cause investigation after a breach.
GRC specialist
Governance, Risk, and Compliance: builds governance frameworks, ensures regulatory compliance, manages audits and risk mitigation.
Core domains of cybersecurity defense
Application, information, network, and operational security; encryption; access control; user education/awareness; disaster recovery and business continuity.
Hardware vs. software
Hardware is the physical components (CPU, motherboard, screen); software is code-based programs running on hardware (apps, operating systems).
Operating system (OS)
Software that manages hardware resources (CPU, memory, storage) and sits between application software and physical hardware.
Virtual machine (VM)
Software that emulates physical hardware and an OS, letting one physical machine host multiple guest operating systems.
Why software is vulnerable
Software is built from source code, and code is imperfect; bugs and logic errors create vulnerabilities attackers exploit.
Case study: Colonial Pipeline
DarkSide ransomware forced a shutdown of a major fuel pipeline supplying much of the U.S. East Coast, triggering state emergencies; a Bitcoin ransom was paid and largely recovered by the FBI.
Case study: SolarWinds Orion
A supply chain attack by APT29 (Cozy Bear) that compromised the software build pipeline, pushing trojanized updates to downstream customers.