Introduction to Information Security and the CIA Triad

Cybersecurity Class Objectives

  • Intellectual Skills & Analysis

    • Analyze various scenarios and accurately map them to the CIA Triad.

    • Differentiate between different types of cyber threats (e.g., Phishing vs. Malware vs. Ransomware).

    • Evaluate various authentication methods such as Passwords, MFA, and Biometrics.

    • Defend data privacy and adhere to ethics, specifically referencing regulations like the General Data Protection Regulation (GDPR).

  • Security-First Mindset & Ethics

    • Internalize the "Zero-Trust" philosophy, which entails questioning everything and engaging others in security practices.

    • Advocate for strong security by adopting secure habits.

  • Hands-on Technical Skills

    • Configure Firewalls and Access Control Lists (ACLs) to manage allowed and denied traffic flow.

    • Generate and deploy cryptographic SSH keys for passwordless remote access.

    • Execute an Incident Response Checklist consisting of five phases: Detect, Contain, Eradicate, Recover, and Post-Incident Review.

The CIA Triad: A Framework for Information Security

  • Confidentiality

    • Simple Definition: Keeping secrets secret. Ensuring only authorized people can read or access specific data.

    • Importance: Prevents identity theft, preserves trade secrets, and maintains both personal and organizational privacy.

    • Working Scenario: A university’s secure payroll portal uses strong encryption so only HR personnel and the individual employee can view salary details.

    • Failure Scenario (The Unlocked Spreadsheet): A school counselor leaves an unencrypted spreadsheet containing student mental health records on a shared public computer, allowing unauthorized students to read the confidential notes.

  • Integrity

    • Simple Definition: Keeping data accurate. Ensuring information is not altered, tampered with, or deleted by accident or malice.

    • Importance: Ensures that decisions are based on completely accurate and untampered information.

    • Working Scenario (Digital Gradebook Hash): A teacher uploads final grades, and the system calculates a unique digital signature or hash for the file. The database checks this hash to prove the grade was not altered from a 'D' to an 'A'.

    • Failure Scenario (The Bank Account Flip): A hacker intercepts a digital bank transfer of P1,000P1,000 and modifies the recipient's account number mid-transit, routing the funds to their own account without the sender's knowledge.

  • Availability

    • Simple Definition: Keeping things accessible. Ensuring authorized users can access data and systems whenever needed.

    • Importance: A secure system is useless if the people who need it are locked out.

    • Working Scenario (Cloud Backup & Redundancy): A hospital stores patient health records on a secure cloud network with backup power generators and redundant servers, ensuring doctors have 24/724/7 access to medical histories.

    • Failure Scenario (Denial-of-Service Attack): A student launches a flood of junk traffic at a school's online portal during a final exam window, crashing the server and preventing anyone from logging in to take the test.

Applying the CIA Triad to a Cisco Packet Tracer Network

  • Network Infrastructure Components

    • Router R1, Firewall / ASA, Switch S1, and Wireless Access Point (AP).

    • Segmented VLANs: PC-Admin (VLAN 10), Web Server (VLAN 20), and File Server / Laptop (VLAN 30).

    • Internet connectivity via Cloud / ISP.

  • Implementation Strategy

    • Confidentiality: Implemented via Firewalls, ACLs, VLANs, and WPA2 Wi-Fi. Access to servers is restricted using ACLs and separate VLANs.

    • Integrity: Implemented through secure protocols like SSH (instead of Telnet) and Port Security on switches to protect device configurations.

    • Availability: Implemented through redundant links, backup servers, and Uninterruptible Power Supplies (UPS) conceptually to ensure uptime and prevent unauthorized shutdowns.

Balancing Security and Usability

  • Password Policies

    • High Security (Low Usability): Users forced to change complex, 1616-character passwords every 3030 days with no repeats or dictionary words. Result: Frustrated users.

    • High Usability (Low Security): Simple, easy-to-remember passwords (e.g., "123456") that never change. Result: Weak shield.

    • User Workaround: Employees write complex passwords on sticky notes and tape them to monitors.

    • The Sweet Spot: Use long passphrases (e.g., "correct-horse-battery-staple") and corporate password managers so users only remember one master key.

  • Identity Verification (MFA)

    • High Security (Low Usability): Mandating a password, an email link, a mobile app code, and a facial scan for every login.

    • High Usability (Low Security): User enters a password once and remains permanently logged in across all devices.

    • User Workaround (MFA Fatigue): Users bombarded with prompts eventually blindly tap "Approve," accidentally letting hackers in.

    • The Sweet Spot (Adaptive MFA): System triggers MFA only if unusual activity is detected, such as a new device, different browser, or unexpected country.

  • Device & Software Updates

    • High Security (Low Usability): Immediate system reboots the minute a patch is released, interrupting active calls and unsaved work.

    • High Usability (Low Security): Updates are optional, allowing users to click "Remind me later" indefinitely.

    • User Workaround: Users disable Windows Update services entirely, leaving systems open to ransomware.

    • The Sweet Spot: Updates are downloaded in the background and scheduled for automatic installation at 2:00 AM2:00\,\text{AM}.

  • Network & Access Controls

    • High Security (Low Usability): Every site and printer requires re-authentication; no remote access is permitted.

    • High Usability (Low Security): All employees have full admin rights and can access any database from any device globally.

    • User Workaround (Shadow IT): Frustrated employees upload sensitive spreadsheets to unsecure personal Google Drive or Dropbox accounts.

    • The Sweet Spot (RBAC & SSO): Role-Based Access Control and Single Sign-On allow users to log in once to a portal that unlocks only the specific tools needed for their job role.

Understanding the Components of Security

  • Vulnerability

    • Definition: A weakness or gap in defense systems; the "crack in the armor."

    • Nature: An internal state that can be patched or fixed.

    • Physical Example: A broken lock on a retail store window.

    • Cyber Example: An outdated operating system on a school computer unpatched for three years.

  • Threat

    • Definition: An external danger (person, event, or force) with the potential to exploit a vulnerability.

    • Nature: An external force that cannot be controlled, only prepared for.

    • Physical Example: A burglar looking for stores to rob.

    • Cyber Example: A ransomware group scanning the internet for outdated operating systems.

  • Risk

    • Definition: The likelihood of a bad event happening combined with the potential damage.

    • Nature: The probability of a loss; only exists when a threat meets a vulnerability.

    • Physical Example: High risk occurs when the burglar (threat) finds the broken lock (vulnerability) and steals the cash register.

    • Cyber Example: High risk occurs when the ransomware group (threat) finds the unpatched computer (vulnerability), encrypts student records, and demands P500,000P500,000.

Network Security Risk Flow Scenarios

  • Scenario 1: Employee PC

    • Vulnerability: Weak password (e.g., 123456123456).

    • Threat: Hacker.

    • Risk: Account compromise leading to an unauthorized login.

  • Scenario 2: Web Server

    • Vulnerability: Outdated software (e.g., version v1.0v1.0).

    • Threat: Malware.

    • Risk: Website compromise and potential data theft.

  • Scenario 3: Router

    • Vulnerability: Default credentials (e.g., "ADMIN").

    • Threat: Attacker.

    • Risk: Full network access granted to the attacker.

  • Scenario 4: Switch

    • Vulnerability: Unused open ports.

    • Threat: Unauthorized device.

    • Risk: Internal network breach.