In-Depth Notes on Cyber Defence Introduction

Module Overview

  • Module Code: 900103-000-00-KM-01
  • Qualification Title: Cybersecurity Defender
  • NQF Level: 4
  • Credits: 7
  • Notional Hours: 70
  • SAQA QUAL ID: SP - 220330

Purpose of the Module

  • Goal: Build an understanding of cybersecurity basics, terminology, and concepts.
  • Focus Areas:
    • Cybersecurity introduction (30%)
    • Cybersecurity basics (20%)
    • Cybersecurity governance fundamentals (20%)
    • A cyber secure organization (15%)
    • Basics of threat intelligence (15%)

Entry Requirements

  • Minimum Level: NQF Level 3 (Grade 11)
  • Subjects: Computer Literacy, English, and Math Literacy

Assessment Criteria

  • Knowledge and understanding of:
    • Governance principles related to cybersecurity
    • Cyber threats and attacks
    • Incident response procedures
    • Ethical considerations in cybersecurity
    • Different hacking techniques and mechanisms against intrusions

Qualification Purpose

  • Cybersecurity Defenders' Role: Protect organizations' systems against attacks, respond to breaches, and harden information systems for compliance with legislation.

Qualification Components

Knowledge/Theory Component (26 Credits)
  • KM-01-KT01: Cyber Defence Introduction (7 Credits)
  • KM-01-KT02: Cyber Threats and Attacks (7 Credits)
  • KM-01-KT03: Cybersecurity (7 Credits)
  • KM-01-KT04: Responding to Cybersecurity Incidents (5 Credits)
Application Component (34 Credits)
  • PM-01: Protect against threats, intrusions, and attacks (11 Credits)
  • PM-02: Detect cybersecurity threats (11 Credits)
  • PM-03: Conduct Penetration Testing Techniques (12 Credits)

Exit Level Outcomes (ELO)

  1. Demonstrate knowledge of cybersecurity concepts.
  2. Protect against cybersecurity attacks.
  3. Detect cybersecurity threats and attacks.
  4. Use penetration testing tools to identify vulnerabilities.

Cybersecurity Concepts and Terminology

Introduction to Cybersecurity (KT0101)
  • Definition: Cybersecurity is protecting systems, networks, and programs from digital attacks.
  • Significance: Critical for safeguarding large-scale systems impacting public services like finance and energy.
Key Principles of Cybersecurity
  • Confidentiality: Protect sensitive information from unauthorized access.
  • Integrity: Ensure data maintains accuracy and consistency.
  • Availability: Guarantee information is accessible to authorized users.
  • Authentication: Verification of user identities.
  • Authorization: Granting access rights based on roles.
  • Encryption: Converting data into secure formats.
  • Firewalls: Protect networks from intrusions.
  • Malware: Software created to harm systems.
  • Phishing: Deceptive attempts to gain sensitive information.
  • Vulnerability: Weaknesses that can be exploited by attackers.

Types of Hackers

  • White Hat Hackers: Ethical hackers who find and fix security issues.
  • Black Hat Hackers: Malicious hackers who exploit vulnerabilities for personal gain.
  • Gray Hat Hackers: Operate without permission but aim to improve security.

Cyberattack Categories

  1. Malware: Viruses, Trojans, and ransomware.
  2. Phishing: Deceptive emails to extract information.
  3. DDoS Attacks: Overloading services to disrupt availability.
  4. SQL Injection: Attacking databases to gain unauthorized access.

Cyber Resilience (KT0106)

  • Definition: Ability to prepare for, respond to, and recover from cyber threats.
  • Key Aspects:
    1. Preparedness and risk assessment.
    2. Detection and response capabilities.
    3. Business continuity planning.

Cybersecurity Governance Fundamentals (KT0301)

  • Legislative Framework: Cybercrimes Act & POPI Act for data protection.
  • Policies: Establish security governance, risk management, and compliance.

Basics of Threat Intelligence (KT0501)

  • Definition: Knowledge of threats to inform security measures.
  • Types:
    • Strategic: Long-term trends and motivations.
    • Tactical: Specific threats and indicators.
    • Operational: Technical data about threats.

Continuous Improvement

  • Regular assessments, risk management, and updates on security measures are essential for a resilient cybersecurity framework.