
Begin your cybersecurity knowledge journey with this beginner course from my cyber league; stay patient, persevere through terms, and the concepts will become clear by completion.
Define data as unorganized facts needing processing to derive information. Identify data as texts or numbers on paper, bytes and bits in devices, or facts stored in the mind.
Identify how data becomes information through processing by machines or humans, with information defined as organized, valuable data that enables timely, complete, and accurate decision making.
Describe the three states of data—data address, data in transit, and data in use by employees—and how protections like non-disclosure or non competence agreements and a need-to-know basis apply.
View data as a valuable asset in the digital era, where accurate information at the right time enables informed decisions and information security protects against misinformation.
Explore how information security protects information systems from unauthorized access and disruption to ensure confidentiality, integrity, and availability, per NIST's mission to promote innovation and industrial competitiveness.
Cyber security is a subset of information security; it protects digital data and devices as per NIST, ensuring availability, integrity, authentication, confidentiality, and non-repudiation.
Explore the CIA triad—confidentiality, integrity, and availability—and how protecting each asset category in balance prevents disclosure, modification, or downtime in real-world cybersecurity.
Explore the CIA triad—confidentiality, integrity, and availability—defining each concept and showing how encryption, hashing, digital signatures, and backups support secure data.
Explore authentication, authorization, and accountability as a trio of controls for governing access to digital resources and auditing user activity.
Learn how authentication determines whether you are who you claim to be by entering credentials like username and password, and how successful authentication grants access to registered courses.
The lecture covers five authentication methods: something you know, something you are, something you have, something you do, and somewhere you are (location), and emphasizes multifactor authentication as best practice.
Understand authorization by comparing it to authenticating a traveler at the airport, then granting access to only authorized resources based on verified identity and subscription.
Accounting records all activities and transactions in log files, detailing when, what, who, and how they occurred, including login attempts and data access, to support cybersecurity investigations.
Explain non reputation as providing proof of a user's action so they cannot deny it, illustrated by a digital signature using a private key.
Learn how authentication verifies a user or subject requesting a resource, then authorization grants access if permission exists, and all actions are logged for accounting.
Compare white hat, black hat, and grey hat hackers by intention. White hats test defenses ethically; black hats steal or ransom; grey hats hack without authorization and risk illegality.
Explore how threat, vulnerability, exploit, risk, and impact interact in a house theft scenario, from a thief identifying a weak lock to the resulting mental distress.
Examine cybersecurity threats as malicious attacks that unlawfully access data, disrupt digital operations, or damage information, and explore five main categories used by threat actors.
Explore malware and its impact, showing how cyber attackers use malicious software to damage data and gain unauthorized network access, including virus, worm, trojan horse, spyware, rootkit, adware, and ransomware.
Explore unauthorized access as a cybersecurity threat. See how bypassing consent, by entering restricted areas or guessing credentials, grants illicit access to data and devices.
Identify how system failure happens when software or operating systems stop functioning. See how the blue screen of death in Windows uses a QR code for quick troubleshooting.
Explore social engineering tactics that manipulate users into revealing confidential information. Learn how phishing emails imitate legitimate senders and lure targets to click malicious links or fake login pages.
Natural calamities such as floods, earthquakes, and hurricanes threaten information and can destroy data centers or computer systems, so plan and implement business continuity and disaster recovery in advance.
Identify threat actors and their types, distinguishing external from internal threat actors who drive or participate in attacks targeting an organization's IP security.
Identify four external threat actor groups: script kiddies with limited skills, hacktivists like Anonymous advocating social change, organized crime for money, and advanced persistent threats backed by nation-states.
Identify internal threat actors—disgruntled employees and unskilled employees—and explain how insiders with greater access can threaten IT infrastructure and data, through data leaks or phishing-driven credential sharing.
Identify vulnerabilities in information systems, including software bugs, misconfigurations, and Heartbleed-like flaws, and learn how vulnerability management reduces risk.
Identify risk as the likelihood of a significant impact from exploiting a vulnerability, shaped by asset criticality and public exploits. Treat threats as external, and control vulnerabilities through patching.
Recognize exposure as the result of a threat actor exploiting a vulnerability to compromise an asset. See data exfiltration or cyber attacks as examples.
Identify the three basic control types—physical, technical, and administrative—and learn how risk mitigation, not elimination, leaves residual risk.
Learn how physical controls protect real-world environments by deploying alarm systems, surveillance cameras, locks, doors, ID badges, and security guards to deter threats.
Explore technical controls as a category of cybersecurity measures, including smartcard access control, intrusion detection system, encryption, and network authentication.
Learn how administrative controls, including security awareness training for people, reduce human risk and complement physical and technical measures while complying with India's IT Act 2000 and GDPR.
Explore six security control functionalities: different, preventive, detective, corrective, recovery, and compensating. Learn to map controls to risk and select effective measures for various situations.
Identify how threat actors exploit vulnerabilities to create risk to assets, and apply controls that deter, prevent, detect, recover, or compensate threats, mitigating impacts like financial loss and reputational damage.
Introduction:
Building your knowledge base is similar to building a house; without a solid foundation, it will be weak, and will fail when it is actually required. In this course my goal will be to lay solid foundation of Cyber Security for you. This course is designed to provide you with a solid foundation in cyber security, covering topics and terms used by Cyber Security Professionals.
What you will be able to do after completion of this course ?
You will be able to understand Cyber Security basics terminologies ( which will be very useful, if you have to collaborate with Cyber Security professionals).
You can take any advance level courses.
Topics Covered:
Course Intro.
What is data ?
What is information ?
State of data information.
Data is equivalent to asset.
Information security definition.
Are Information Security & Cyber Security same ?
CIA Triad (Objectives of Cyber Security)
Summarization Of CIA
AAA of Security Introduction.
Authentication
Five Methods Of Authentication
Authorization
Accounting
Non-Repudiation
Summarization Of AAA
Types Of Hackers.
Scenario To Understand Threat, Vulnerability, Exploit, Risk & Impact.
Cyber Security Threats
Threat Category - Malware
Threat category - Un-authorized Access.
Threat category - System Failure.
Threat Category - Social Engineering
Threat Category - Natural Calamities
Threat actors and it's types
Threat actor - External
Threat Actor - Internal
Vulnerabilities
Risk
Exposure
Types of controls: Physical, Technical, Administrative,
Functionalities Of Security Controls.
Summarization of threat actor, threat, vulnerability, risk and impact.