Lesson 1

Course Overview, Instructor Team, and University Resources

  • Instructor Profile

    • Instructor: Professor Chris Sebora, Lt Col, USAF (ret).

    • Position: Lecturing Professor of Information Sciences and Technology.

    • Military Background: Served 23 years in the United States Air Force (USAF).

    • Academic Experience: Served 3 years as an IST Academic Adviser.

    • Professional Expertise: Aviation, IT Consulting, Staff Officer, and Commander.

    • Personal Hobbies: Golf, house renovation, veteran support services, and travel.

  • Teaching and Learning Assistants (TAs / LAs)

    • Role: Serve as learning coaches and mentors to assist undergraduate students.

    • Selection Requirements:

    • Talented undergraduates who previously completed SRA 111 with a grade of A or A-.

    • Academic standing with a cumulative GPA greater than 3.2 (GPA>3.2\text{GPA} > 3.2).

    • Strong communication skills, demonstrated initiative, and a commitment to helping peers.

    • Office Hours: Scheduled via Microsoft Bookings.

  • Personal Operational Principles

    • Focus on three daily controllable factors:

    1. Be on time for all assignment deadlines.

    2. Maintain a positive attitude.

    3. Provide maximum effort.

    • Key Mantras:

    • "Prior Preparation Prevents Poor Performance."

    • "A lack of preparation on your part does not constitute an emergency on my part."

  • University Support Resources

    • Student Care and Advocacy: Provides holistic assistance during major life events, crisis situations, or prolonged absences, coordinating directly with course faculty.

    • Counseling and Psychological Services (CAPS): Offers up to 5 initial counseling appointments covered through student fees; appointments can be scheduled online.

    • Student Disability Resources: Provides academic support, accommodations, and guidance for students with diagnosed learning disabilities.

    • Academic Advisers: Assist students with broader academic path planning, degree tracking, and institutional guidance beyond course registration.

    • Faculty & LA Office Hours: Designed for early academic check-ins and support, operating on the principle that bad news does not improve with time.

Core Objectives, Principles, and Requirements of SRA 111

  • Course Overview

    • SRA 111 is an introductory course designed to broad-spectrum security and risk concepts.

    • Foundational Values: Grounded in respect for technology, diverse cultures, and the law.

    • Design Imperatives: Centers on the structural role of Data, Analytics, Policy, and Law.

    • Skill Development: Challenges students in critical thinking, analytical writing, and complex problem-solving.

    • Central Analytical Theme: Understanding uncertainty and developing methodologies to analyze, quantify, and prepare for it.

  • Primary Course Learning Objectives

    • Correctly utilize core risk terminology across analytical contexts.

    • Consistently evaluate and analyze risks across multiple operational domains.

    • Communicate risk findings clearly, concisely, and persuasively.

  • Detailed Programmatic Goals

    • Fundamentals of Risk: Define, identify, and put into practice core principles of risk analysis in daily life and formal security decision-making.

    • Threat-Risk Environment: Derive, analyze, and apply elements defining the threat-risk environment across individual, group, and organizational levels.

    • Analytic Writing: Demonstrate sound analytic writing principles by effectively communicating research and assessment findings through written reports, evaluated primarily via a semester team project.

    • Critical Thinking: Apply structured reasoning and critical communication techniques to practical risk and threat problems.

    • Tools, Methods & Application: Utilize structured risk identification and assessment frameworks to address real-world risk problems.

    • Bridging Theory and Practice: Translate theoretical risk concepts into practical threat-risk evaluations and present findings clearly.

  • Blended Learning Model

    • Course structure integrates traditional Face-to-Face (F2F) classroom interaction with asynchronous online components.

    • Core Student Requisites: Preparation, Participation, Patience, and Active Feedback.

    • Instructional Components: Attendance tracking, video lectures, real-world case studies, and journaling exercises.

Blended Learning Model Combining Face-to-Face and Online Learning

Safety Protocols, Evacuation Plans, and Emergency Responses

  • Westgate Building (Westside) 1st Floor Evacuation Routes

    • West Westgate (W201):

    • Designated Primary Meeting Site: Bottom of the West Westgate ramp at the pedestrian cross-walk.

    • Inclement Weather Assembly Site: Earth & Engineering Science Building.

    • East Westgate:

    • Designated Primary Meeting Site: Bottom of the East Westgate ramp along Burrowes Street.

    • Inclement Weather Assembly Site: Deike Building.

Westgate Building Westside 1st Floor Evacuation Route
  • Active Attacker Response Protocol

    • Official Penn State protocol follows the standard Run, Hide, Fight framework:

    • Run: Evacuate the facility immediately if a clear, safe escape path is available. Leave belongings behind and prevent others from entering.

    • Hide: If evacuation is impossible, secure yourself in an enclosed room, lock and barricade doors, silence mobile devices, and remain out of sight.

    • Fight: As an absolute last resort when in imminent danger, commit to physical action to disrupt or incapacitate the attacker using improvised weapons.

Penn State Active Attacker Protocol - Run, Hide, Fight

Evaluation Mechanics, Policies, and Academic Integrity

  • Course Logistics and Communication

    • Total Course Enrollment: 65 students.

    • Course Prerequisites: None; all necessary reading materials are distributed via Canvas.

    • Official Communication Channel: All direct communication with the teaching team must occur through Canvas Mail.

    • Weekly Schedule Rhythm:

    • Mondays: Formal core lectures.

    • Wednesdays & Fridays: In-class practical group activities and application workshops with faculty and LA guidance.

    • Question Protocol: In-class questions asked and answered will not be repeated; for online queries, students must consult LAs before escalating to the instructor.

  • Evaluation Structure and Grading Categories

    • Discussion & Participation: Evaluated individually; the lowest 2 discussion post scores are automatically dropped.

    • Individual Assignments: Submitted individually (includes recurring "In the News" analytic assignments).

    • Unit Exams / Quizzes: A total of five individual and group in-class exams replace traditional weekly quizzes.

    • Midterm Exam: Individual written paper exam administered in class.

    • Semester Team Project / Final Brief: The main team deliverable, completed and submitted in structured parts across the semester, replacing the traditional final exam.

SRA 111 Graded Assignment Overview
  • Course Submission Policies

    • Late Work Policy: Assignments submitted more than 2 days past the published deadline will receive zero credit unless pre-approved.

    • Grade Dispute Window: Students have exactly 1 week after grades post to notify all course instructors via the Canvas email group and request a review during office hours. Students are responsible for verifying that uploaded files are complete and readable.

    • Email Response Window: Standard response time target is within 2 business days (Monday through Friday).

  • Academic Integrity Policy

    • Policy Foundation: Industry-driven standards designed to protect degree and diploma integrity.

    • Mandatory Requirement: Completion of the AI "Acknowledgement" Assignment posted on the Canvas Calendar.

    • Violation Sanction Scale (Illustrated using a 100-point Quiz example):

    • First Violation: Gradebook penalty deducting 50% of the maximum assignment value (-50 points on a 100-point assignment). Maximum achievable final course grade capped at 85%.

    • Second Violation: Gradebook penalty deducting 100% of the maximum assignment value (-100 points). Maximum achievable final course grade capped at 65%.

    • Third Violation: Automatic course failure (FF grade).

Attendance Requirements and Class Community

  • Attendance Logistics and TopHAT Verification

    • Attendance is mandatory across approximately 30 scheduled class sessions.

    • Verification Method: Recorded via the TopHAT app, requiring location services enabled on mobile devices during class.

    • Frequency: TopHAT checks occur twice per class—once within the first 15 minutes, and once within the final 15 minutes. Credit requires responding to both check-ins; no partial credit is awarded.

    • Attendance is recorded as an independent policy requirement and does not count toward the participation grade.

    • Non-excused Absences: Social engagements, family reunions, and weddings are not excused absences.

  • Absence Penalty Structure

    • Allowed Absence Threshold: Students are granted 7 no-questions-asked absences per semester without penalty or documentation.

    • Penalty Cap Scale: Beyond 7 absences, each additional missing class drops the student's maximum possible overall course grade cap by 10%:

    • 7 or fewer absences: No penalty (Maximum possible grade = 100%).

    • 8 absences: Maximum possible final grade capped at 90% (AA- max).

    • 9 absences: Maximum possible final grade capped at 80% (BB- max).

    • 10 absences: Maximum possible final grade capped at 70% (CC- max).

  • Historical Student Grade Distribution

    • Data derived from 1,600 total students across 8 academic terms:

    • 62% earned an A grade.

    • 27% earned a B grade.

    • 8% earned a C grade.

    • 1% earned a D grade.

    • 2% earned an F grade (attributable almost entirely to non-compliance with the attendance policy).

  • Classroom Community Research

    • Classroom culture relies on collective communication, collaborative group tasks, and linking real-world events to academic concepts.

    • According to McMillan & Chavis (1986), students who report a strong sense of community within the classroom demonstrate higher statistical rates of:

    1. Regular class attendance.

    2. Active in-class participation.

    3. Successful college graduation.

Key Risk and Analysis Vocabulary

  • Risk

    • Definition: The possibility that a harmful event will occur and result in negative consequences ("What could go wrong, and why does it matter?").

    • Core Focus: Focuses on potential outcomes rather than underlying causes.

    • Mathematical Nature: Functionally combines Likelihood and Impact.

    • Temporal Existence: Exists continuously as a potential state, even before an actual incident occurs.

  • Threat

    • Definition: An actor, event, or force capable of causing harm by exploiting vulnerabilities to create risk.

    • Categories:

    • Human Threats: Intentional threat actors (e.g., ransomware syndicates, state-sponsored cyber attackers).

    • Natural Threats: Environmental events (e.g., hurricanes, floods, earthquakes).

    • Accidental Threats: Unintentional operational events (e.g., human operator error, misconfigurations).

  • Vulnerability

    • Definition: A physical, technical, operational, or administrative weakness that can be exploited by a threat actor or event to realize risk.

    • Categories:

    • Technical Vulnerabilities: Missing patches, unencrypted channels, absence of Multi-Factor Authentication (MFA).

    • Organizational Vulnerabilities: Unenforced security policies, inadequate training, lack of oversight.

    • Human Vulnerabilities: Credential reuse, susceptibility to phishing, poor operational security.

  • Impact / Consequence

    • Definition: The magnitude or severity of harm realized if a risk event occurs ("So what?").

    • Key Dimensions:

    • Financial loss (direct recovery costs, lost revenues, legal fines).

    • Operational disruption (system downtime, supply chain paralysis).

    • Public or societal harm (threats to safety, environmental damage, critical infrastructure failure).

    • Political or reputational damage (loss of consumer trust, regulatory penalties).

  • Likelihood / Probability

    • Definition: An estimated assessment of the chance or frequency that a specific risk event will manifest.

    • Analytical Principle: Likelihood is assessed based on historical data, vulnerability exposure, and threat trends, rather than predicted with complete certainty.

  • Exposure

    • Definition: The extent, scale, or value of assets and entities subject to potential harm if a risk occurs.

    • Operational Effect: Higher exposure directly increases total potential impact (e.g., total registered users, global operational regions, critical system dependencies).

  • Hazard

    • Definition: A foundational condition, situation, or environment that creates or increases the potential for harm.

    • Operational Nature: Systemic or environmental state existing prior to a specific threat incident, combining contextual parameters and system capabilities.

  • Risk Appetite

    • Definition: The broad amount and type of risk an organization is intentionally willing to accept in pursuit of its strategic objectives.

    • Organizational Role: Established by leadership prior to incidents, reflecting organizational values, resource constraints, cost considerations, and strategic speed.

  • Risk Tolerance

    • Definition: The specific, measurable boundaries and quantitative limits an organization establishes that it will not exceed.

    • Examples: Maximum allowable system downtime (e.g., < 2 hours), maximum acceptable financial loss thresholds, strict zero-tolerance regulatory limits.

  • Uncertainty

    • Definition: The state of missing, incomplete, or unknowable information facing analysts when assessing situations.

    • Analytical Reality: Risk decisions must be executed under conditions of uncertainty rather than waiting for complete information.

    • Key Factors: Unknown adversary capabilities, undisclosed zero-day vulnerabilities, unpredictable human reactions, and unknown system recovery timelines.

Real-World Risk Metaphors and Public Safety

  • The Risk Avoidance Paradox (N+1N + 1 Risks)

    • Metaphorical Illustration: Featured in Hardin's organizational risk cartoon: "We've considered every potential risk except the risks of avoiding all risks."

    • Analytical Concept: Attempting to eliminate all known operational risks (NN) inherently generates new, unmanaged risks (N+1N + 1), such as organizational stagnation, extreme operational inefficiency, or unmonitored alternative workarounds.

Hardin Risk Management Cartoon - N+1 Risks
  • Public Safety Risk Principles: "Turn Around Don't Drown" (NOAA / NWS / FEMA)

    • Physical Flood Mechanics:

    • Just 12 inches (12inches12\,\text{inches}) of swift-flowing water generates enough buoyant force to carry away a small passenger automobile.

    • 18 to 24 inches (1824inches18\text{--}24\,\text{inches}) of flowing water can sweep away large vehicles, including trucks, SUVs, and emergency response apparatus.

    • Fatality Data: Over 50% of annual flood-related fatalities occur within motor vehicles.

    • FEMA Mobile Application Features:

    • Prepare: Provides safety recommendations and emergency supply kit assembly checklists.

    • Weather Alerts: Delivers real-time warnings directly from the National Weather Service.

    • Disaster Resources: Assists users in locating shelters and applying for federal assistance.

    • Disaster Reporter: Enables citizens to share geotagged disaster photographs.


Cybersecurity as a Business and Societal Issue: Colonial Pipeline Case Study

  • Defining Security & Risk Analysis

    • Study of system vulnerabilities, potential failure modes, consequence evaluations, and decision-making under uncertainty.

    • Cybersecurity vs. Risk Analysis:

    • Cybersecurity: Focuses on technical controls, software vulnerabilities, attack vectors, and defensive tools.

    • Risk Analysis: Focuses on operational outcomes, business continuity, societal impacts, and strategic tradeoffs.

  • Colonial Pipeline Case Study Overview

    • Background: Colonial Pipeline operates the largest refined petroleum pipeline system in the United States, transporting millions of barrels per day across the East Coast.

    • Initial Compromise Vector: Threat actors gained entry using a single compromised legacy Virtual Private Network (VPN) account credential that lacked Multi-Factor Authentication (MFA).

    • Execution: Ransomware encrypted corporate IT and billing network infrastructure.

    • Proactive Operational Shutdown: Fearing the malware might jump from corporate IT to Operational Technology (OT) networks controlling physical pipeline valves, operators proactively shut down the pipeline.

    • Systemic Cascading Consequences:

    • Caused immediate fuel supply shortages across multiple states.

    • Sparked regional panic buying, price spikes, and service station outages.

    • Transformed an IT cybersecurity incident into a major national supply chain and economic security crisis.

    • Prompted high-level federal policy, regulatory, and congressional scrutiny.

  • Root Cause Vulnerabilities & Preventive Controls

    • Vulnerabilities Exploited: Credential reuse/weakness, absence of MFA, lack of network isolation.

    • Essential Controls Required:

    • Implementation of mandatory Multi-Factor Authentication (MFA).

    • Robust network segmentation isolating IT business networks from critical OT pipeline controls.

    • Eliminating single points of operational failure.

  • Tradeoffs and Business Realities

    • Organizational Delays: Security enhancements are frequently delayed due to implementation costs, operational friction, user inconvenience, and legacy system complexity.

    • Non-Financial Costs: Security failures impose severe non-monetary costs including brand erosion, loss of public trust, loss of market confidence, and increased regulatory burdens.

How We Reason About Risk: Emotional Intelligence, Perception, and Disagreement

  • Emotional Intelligence (EI) in Risk Reasoning

    • Definition: "The ability to monitor one's own and other's emotions, to discriminate among them, and to use the information to guide one's thinking and actions" (Chapman & Co).

    • Impact on Rationality: Although humans aim to be rational thinkers, intense emotional states—specifically Fear, Affection, and Hatred—cause significant departures from sound logical thinking.

    • Degradation of Heuristics: Emotional interference alters cognitive heuristics (mental shortcuts used for problem-solving), leading analysts to:

    • Substitute easier, less relevant questions to guide complex analysis.

    • Display excessive confidence in unverified personal beliefs.

    • Fail to acknowledge critical gaps in knowledge or evidence.

  • Paul Graham's Hierarchy of Disagreement

    • Evaluates the structural effectiveness of arguments across seven levels, ranging from emotional, ineffective responses to high-level refutation:

    1. Name-Calling (Lowest level): Direct verbal insults devoid of substantive claims (e.g., "You are an ass hat.").

    2. Ad Hominem: Attacking the author's personal characteristics, credentials, or authority without addressing the underlying argument.

    3. Responding to Tone: Criticizing the tone, style, or language of the author while ignoring the factual substance.

    4. Contradiction: Stating an opposing counter-claim with minimal or no supporting evidence.

    5. Counterargument: Contradicting the original claim while providing supporting evidence and structured reasoning.

    6. Refutation: Spotting specific mistakes or logical flaws, quoting the original text, and explaining why it is incorrect.

    7. Refuting the Central Point (Highest level): Explicitly identifying, targeting, and disproving the core thesis of the opposing argument.

Paul Graham's Hierarchy of Disagreement Pyramid
  • Analysis and Perception: The Puzzle Analogy

    • Puzzle Framework: Comparing a 250-piece puzzle to a 1,000,000+ piece puzzle demonstrates that while the core task remains identical, the scale drastically alters analytical perception.

    • Hindsight Fallacy: Claims such as "They should have put all the pieces together!" represent post-event hindsight bias rather than valid prospective analysis.

    • Subjectivity of Perception: As literary critic Edmund Wilson observed: "…no two persons ever read the same book. The cover, paper, typeface and words can be exactly the same but the response will be unique."

    • Key Influences on Human Perception:

    • Past operational experiences.

    • Educational background.

    • Cultural values and norms.

    • Organizational roles and expectations.

    • Personal attitudes, interests, and emotional bias.

    • Time constraints and environmental setting.

Cognitive Biases and Structured Analytic Techniques

  • Understanding Cognitive Bias

    • Definition: A pre-conceived mental preference, systematic shortcut, or unconscious inclination that impairs objective evaluation.

    • Impact on Risk Analysis: Causes analysts to overlook emerging threats, improperly score risk matrices, or prematurely dismiss critical intelligence.

  • Three Key Cognitive Biases in Risk Analysis

    1. Status Quo Bias: The cognitive preference for maintaining current conditions or selecting options with the lowest perceived immediate friction, even when alternative choices offer superior risk mitigation.

    2. Confirming-Evidence Bias: The tendency to actively seek out, weight, and remember information that confirms existing hypotheses while ignoring, discounting, or reinterpreting conflicting evidence.

    3. Anchoring Bias: The tendency to disproportionately weight the first piece of information received when making subsequent estimates, risk scoring, or evaluations.

  • Applying Bias Awareness to Risk Matrices

    • Prior to scoring likelihood and impact ratings in risk models (such as the Colonial Pipeline risk matrix), analysts must actively evaluate their reasoning:

    • Am I anchoring on the initial likelihood or impact score that popped into my head?

    • Am I favoring data that confirms what I expected the risk profile to look like?

    • Am I selecting a "status quo" rating because it is easiest to justify to leadership?

  • Structured Analytic Techniques (SATs)

    • Tools developed by the intelligence community (Tradecraft Primer, 2009) to bypass cognitive mindsets and reduce bias:

    • Sorting

    • Problem Restatement

    • Brainstorming

    • Pros-Cons-and-Fixes

    • Chronologies & Timelines

    • Causal Flow Diagrams

    • The Risk Matrix

    • Decision / Event Trees

    • Weighted Ranking

    • Key Assumptions Checks

    • Devil's Advocacy

    • Team A / Team B Analysis

    • What-If? Analysis

    • Red Cell Exercises

    • Analysis of Competing Hypotheses (ACH)

  • Core Steps to Master Critical Thinking

    1. Explicitly recognize personal cognitive tendencies and natural biases.

    2. Cultivate structured habits to evaluate events using alternate explanations.

    3. Continuously challenge information sources and underlying assumptions.

    4. Focus rigorously on identifying what is unknown or missing.

    5. Maintain an active attitude of "healthy skepticism" across all analytical steps.