Introduction to Information Security and the CIA Triad
Cybersecurity Class Objectives
Intellectual Skills & Analysis
Analyze various scenarios and accurately map them to the CIA Triad.
Differentiate between different types of cyber threats (e.g., Phishing vs. Malware vs. Ransomware).
Evaluate various authentication methods such as Passwords, MFA, and Biometrics.
Defend data privacy and adhere to ethics, specifically referencing regulations like the General Data Protection Regulation (GDPR).
Security-First Mindset & Ethics
Internalize the "Zero-Trust" philosophy, which entails questioning everything and engaging others in security practices.
Advocate for strong security by adopting secure habits.
Hands-on Technical Skills
Configure Firewalls and Access Control Lists (ACLs) to manage allowed and denied traffic flow.
Generate and deploy cryptographic SSH keys for passwordless remote access.
Execute an Incident Response Checklist consisting of five phases: Detect, Contain, Eradicate, Recover, and Post-Incident Review.
The CIA Triad: A Framework for Information Security
Confidentiality
Simple Definition: Keeping secrets secret. Ensuring only authorized people can read or access specific data.
Importance: Prevents identity theft, preserves trade secrets, and maintains both personal and organizational privacy.
Working Scenario: A university’s secure payroll portal uses strong encryption so only HR personnel and the individual employee can view salary details.
Failure Scenario (The Unlocked Spreadsheet): A school counselor leaves an unencrypted spreadsheet containing student mental health records on a shared public computer, allowing unauthorized students to read the confidential notes.
Integrity
Simple Definition: Keeping data accurate. Ensuring information is not altered, tampered with, or deleted by accident or malice.
Importance: Ensures that decisions are based on completely accurate and untampered information.
Working Scenario (Digital Gradebook Hash): A teacher uploads final grades, and the system calculates a unique digital signature or hash for the file. The database checks this hash to prove the grade was not altered from a 'D' to an 'A'.
Failure Scenario (The Bank Account Flip): A hacker intercepts a digital bank transfer of and modifies the recipient's account number mid-transit, routing the funds to their own account without the sender's knowledge.
Availability
Simple Definition: Keeping things accessible. Ensuring authorized users can access data and systems whenever needed.
Importance: A secure system is useless if the people who need it are locked out.
Working Scenario (Cloud Backup & Redundancy): A hospital stores patient health records on a secure cloud network with backup power generators and redundant servers, ensuring doctors have access to medical histories.
Failure Scenario (Denial-of-Service Attack): A student launches a flood of junk traffic at a school's online portal during a final exam window, crashing the server and preventing anyone from logging in to take the test.
Applying the CIA Triad to a Cisco Packet Tracer Network
Network Infrastructure Components
Router R1, Firewall / ASA, Switch S1, and Wireless Access Point (AP).
Segmented VLANs: PC-Admin (VLAN 10), Web Server (VLAN 20), and File Server / Laptop (VLAN 30).
Internet connectivity via Cloud / ISP.
Implementation Strategy
Confidentiality: Implemented via Firewalls, ACLs, VLANs, and WPA2 Wi-Fi. Access to servers is restricted using ACLs and separate VLANs.
Integrity: Implemented through secure protocols like SSH (instead of Telnet) and Port Security on switches to protect device configurations.
Availability: Implemented through redundant links, backup servers, and Uninterruptible Power Supplies (UPS) conceptually to ensure uptime and prevent unauthorized shutdowns.
Balancing Security and Usability
Password Policies
High Security (Low Usability): Users forced to change complex, -character passwords every days with no repeats or dictionary words. Result: Frustrated users.
High Usability (Low Security): Simple, easy-to-remember passwords (e.g., "123456") that never change. Result: Weak shield.
User Workaround: Employees write complex passwords on sticky notes and tape them to monitors.
The Sweet Spot: Use long passphrases (e.g., "correct-horse-battery-staple") and corporate password managers so users only remember one master key.
Identity Verification (MFA)
High Security (Low Usability): Mandating a password, an email link, a mobile app code, and a facial scan for every login.
High Usability (Low Security): User enters a password once and remains permanently logged in across all devices.
User Workaround (MFA Fatigue): Users bombarded with prompts eventually blindly tap "Approve," accidentally letting hackers in.
The Sweet Spot (Adaptive MFA): System triggers MFA only if unusual activity is detected, such as a new device, different browser, or unexpected country.
Device & Software Updates
High Security (Low Usability): Immediate system reboots the minute a patch is released, interrupting active calls and unsaved work.
High Usability (Low Security): Updates are optional, allowing users to click "Remind me later" indefinitely.
User Workaround: Users disable Windows Update services entirely, leaving systems open to ransomware.
The Sweet Spot: Updates are downloaded in the background and scheduled for automatic installation at .
Network & Access Controls
High Security (Low Usability): Every site and printer requires re-authentication; no remote access is permitted.
High Usability (Low Security): All employees have full admin rights and can access any database from any device globally.
User Workaround (Shadow IT): Frustrated employees upload sensitive spreadsheets to unsecure personal Google Drive or Dropbox accounts.
The Sweet Spot (RBAC & SSO): Role-Based Access Control and Single Sign-On allow users to log in once to a portal that unlocks only the specific tools needed for their job role.
Understanding the Components of Security
Vulnerability
Definition: A weakness or gap in defense systems; the "crack in the armor."
Nature: An internal state that can be patched or fixed.
Physical Example: A broken lock on a retail store window.
Cyber Example: An outdated operating system on a school computer unpatched for three years.
Threat
Definition: An external danger (person, event, or force) with the potential to exploit a vulnerability.
Nature: An external force that cannot be controlled, only prepared for.
Physical Example: A burglar looking for stores to rob.
Cyber Example: A ransomware group scanning the internet for outdated operating systems.
Risk
Definition: The likelihood of a bad event happening combined with the potential damage.
Nature: The probability of a loss; only exists when a threat meets a vulnerability.
Physical Example: High risk occurs when the burglar (threat) finds the broken lock (vulnerability) and steals the cash register.
Cyber Example: High risk occurs when the ransomware group (threat) finds the unpatched computer (vulnerability), encrypts student records, and demands .
Network Security Risk Flow Scenarios
Scenario 1: Employee PC
Vulnerability: Weak password (e.g., ).
Threat: Hacker.
Risk: Account compromise leading to an unauthorized login.
Scenario 2: Web Server
Vulnerability: Outdated software (e.g., version ).
Threat: Malware.
Risk: Website compromise and potential data theft.
Scenario 3: Router
Vulnerability: Default credentials (e.g., "ADMIN").
Threat: Attacker.
Risk: Full network access granted to the attacker.
Scenario 4: Switch
Vulnerability: Unused open ports.
Threat: Unauthorized device.
Risk: Internal network breach.