
Explore the CIA triad, risk management, cryptography basics, and key concepts in authentication and authorization while surveying common cybersecurity attacks.
Trace the origins of information security from ARPANET to mitigating information risks. Explore encryption, secure communications, and protection of hardware and software to guard information.
Explore information security, physical security, fraud, and cybersecurity, and learn how policies, compliance monitoring, incident management, and network security protect organizations.
Explore the CIA triad—confidentiality, integrity, and availability—and how encryption and access controls protect data across storage, transit, and processing.
Explore key information security concepts beyond the CIA triad, including sensitivity, concealment, secrecy, privacy, isolation, and non-repudiation. Understand usability, accountability, accessibility, discretion, and criticality to strengthen policy and audits.
Learn how authentication proves who you are and authorization determines what you may access, illustrated by data center ID cards, PINs, and access controls.
Explore the basics of cryptography, including plaintext, encryption, ciphertext, and decryption. Learn symmetric and asymmetric keys, with public and private keys, and see Caesar cipher as a historical example.
Differentiate risk, threat, and vulnerability, and learn how threats and vulnerabilities drive cyber risk. Apply threat assessments, penetration testing, and vulnerability management to reduce risk and protect assets.
Security governance, defined by NIST, builds a framework to align information security with business objectives and laws while assigning responsibility across leadership and staff.
Explore the role of security policies as living, clear documents that govern access to information systems; distinguish policies from procedures and learn to monitor, enforce, and update them.
Conduct a security audit to review an organization’s IT infrastructure, policies, procedures, and compliance with privacy laws and regulations. Identify vulnerabilities and report remediation steps through a third party audit.
Engage in ongoing security risk management by identifying risks, evaluating them against data value and countermeasure costs, and implementing cost-effective plans to reduce risk and support the organization's mission.
Define data privacy as information privacy and describe the global landscape of sector-specific laws, noting no single comprehensive law. Stay up to date, ensure compliance, and adopt third-party certifications.
Integrate security into the software development life cycle, apply OWASP Top 10 guidance, and enforce secure design, secure coding, and post deployment maintenance.
Explore the fundamentals of hacking and common cyber threats, including motives like data theft and reputation damage, and learn about key attacks and the OWASP Top Ten.
Discover how phishing uses social engineering to steal credentials and deploy malware through fake emails and landing pages, including AD credentials and single sign-on in targeted and mass campaigns.
Understand how denial of service attacks disrupt legitimate activity through DoS and DDoS, using botnets to flood networks and exploit OS, software, or protocol flaws.
Identify viruses, worms, and malware by definitions and behaviors; learn how viruses attach to software, worms spread through networks, trojan horses steal information, and ransomware and spyware fit into malware.
Explore SQL injection, an input validation attack where injected SQL queries via user input can read, modify, or delete data, or execute administration tasks.
This course is meant for anyone curious about InfoSec and just starting out in this field. Terminology and concepts are explained with the goal of being clear even to those who hear of them for the very first time.
The following topics are covered mainly with definitions and theoretical explanations, but also with some practical examples:
- The need for InfoSec
- CIA Triad (Confidentiality, Integrity, Availability)
- Non-repudiation
- Risk Assessment & Risk Management
- Cryptography and it's place in InfoSec
- Authentication and Authorization
- Governance and Information Security Policies
- Security Auditing
- Laws & Regulations related to Security and Privacy of Data
- Security Detection and Response
- Vulnerability Management
- Security Patching
- Penetration Testing
As an experienced Cybersecurity expert, I've changed a few roles and seen different approaches to security, mainly in large corporations. I'm happy to provide insight into how those systems operate, and more importantly, how they're secured. You will learn that it's not all about advanced technology you hear about these days, but also about people, processes, education, and analytical thinking. I truly hope you will find value in these lessons, and feel free to reach out shall you have any questions, suggestions, or ideas to share.
Later on, I will add tests in between lessons, including some additional information on differences between all the security disciplines: infosec, cybersec, physical, fraud...