
Discover the CIA triad—confidentiality, integrity, and availability—and learn what each objective means, why it matters, and how it applies to real-world security.
Learn the meaning and importance of confidentiality as the first pillar of the CIA triad, and how encryption, two-factor authentication, and secure disposal protect information from unauthorized disclosure.
Master the integrity pillar of the CIA triad by learning how data stays accurate and unaltered through encryption, checksums, and access controls to prevent tampering and fraud.
Explore availability as the CIA triad’s third pillar, ensuring timely and reliable access for the right people. See how failover, DRP, UPS, and load balancing protect availability.
Explore four types of security: ICT security, information security, cyber security, and physical security, and learn how they differ and connect to protect systems, data, and infrastructure.
Protects the technologies we use to transmit information, transmitter, medium, and receiver, to keep communications reliable. Defines ICT security as broader than IT security.
Learn how information security protects data in all forms—from paper to digital assets—through the CIA triad of confidentiality, integrity, and availability, with cybersecurity as a specialized branch within information security.
Explore cybersecurity as the digital-focused branch of information security that protects digital assets—networks, systems, and data—across local, cloud, and internet environments. Focus on the CIA triad—confidentiality, integrity, and availability.
Implement physical security to protect buildings, equipment, and sensitive data from unauthorized access, theft, and damage, and learn how locks, cameras, guards, backup power, and fire suppression reinforce cybersecurity.
Explore governance, risk management and compliance (GRC) and learn how organizations stay on track, manage risks, and follow rules. Understand why GRC matters and how it applies in real-world situations.
Define risk as the likelihood times impact, visualize it on a five-by-five heat map, and recognize that risk arises when a threat exploits a vulnerability.
Explore the three risk layers—governance, risk management, and risk assessment—and understand how identification, analysis, evaluation, response, and monitoring guide informed risk decisions and organizational resilience.
Risk governance sets a clear direction and continuously monitors its adherence, ensuring a common view of risk, integrated risk management, risk-aware decisions, and effective controls.
Compare qualitative and quantitative risk analysis approaches, showing how expert judgment and heatmaps assess likelihood and impact, while quantitative analysis uses Ale, SLA, and R0 to quantify financial risk.
Discover risk response options—transfer, accept, reduce, and avoid—and learn Tara’s framework with examples like outsourcing, risk mitigation, and GDPR-related considerations.
Explore the various types of malware, or malicious software, and learn how they operate, differ from one another, and cause damage by stealing information, disrupting systems, or gaining unauthorized access.
Identify what viruses are, how they replicate and spread through file systems and networks, how user action activates damage, and risks from data loss, performance slowdown, and information theft.
Define worms as self-propagating malware that spreads across networks without user interaction, exploiting vulnerabilities to infect systems and cause widespread damage.
Learn how keyloggers operate as stealthy malware that secretly track and record every keystroke, whether software or hardware, capturing passwords, credit card numbers, and private data in real time.
Ransomware is an extortive malware that locks or encrypts data and demands ransom, often in cryptocurrency, for a decryption key. It spreads through phishing and vulnerabilities, threatening individuals and organizations.
Identify how Trojan horses disguise as legitimate software to trick you into installing them and stealing data. Stay vigilant against phishing emails and suspicious downloads that deliver backdoors.
Explore rootkit malware that embeds deeply in the operating system to hide other malware, enable long-term control, and evade security tools.
Adware is a malware that floods devices with ads and tracks activity for revenue. It sneaks in via bundled software and fake updates, and you can detect and prevent it.
Explore security controls as vital measures that protect systems, networks, and data from threats, covering common categories, how they function, how they differ, and their role in a cybersecurity strategy.
Understand preventative, detective, and corrective controls across physical, technical, and administrative types, with examples like fences, firewalls, and logs, to reduce risk and manage incidents.
Explore the OWASP top ten, a global standard for identifying and mitigating web application security risks, and prioritize vulnerabilities with step-by-step explanations and actionable guidance.
Explore broken access control, a top OWASP vulnerability, and how weak permission checks allow data access or account takeovers; learn prevention with least privilege and server-side verification.
Explore cryptographic failures in the OWASP top ten, including insecure encryption and rainbow table risks, and learn fixes like password salting and proper key management.
Explore injection vulnerabilities in web apps. Learn to prevent them with input validation and parameterized queries, and review a real-world SQL injection example from the OWASP top ten.
Explore insecure design as a critical OWASP top ten vulnerability. Learn how architecture flaws create data breaches and unauthorized access risks, and how threat modeling builds security into the design.
Identify security misconfigurations, such as default settings, exposed sensitive files, and overly permissive access, and prevent them with regular reviews, hardening, and automated scans.
Learn how vulnerable and outdated components, including plugins and libraries, create security risks and how to identify, update, and monitor them, with an OWASP top ten focus.
Identify and mitigate identification and authentication failures by enforcing strong password policies, avoiding weak passwords, preventing credential stuffing, implementing multi-factor authentication, and securing session management per OWASP top ten.
Explore how integrity failures from the OWASP top ten enable tampering with updates and pipelines, and learn to implement integrity checks, digital signatures, and secure CI/CD to prevent attacks.
Prevent security incidents by implementing centralized logging, real-time monitoring, and alerting across systems. Without visibility, attackers can operate undetected, escalate privileges, or exfiltrate data.
Explore server-side request forgery (ssrf), a key OWASP top ten vulnerability that lets attackers leverage a trusted server to access internal or external resources.
Learn to interact with the Unix operating system using the command line to manage files, navigate directories, and handle system processes, gaining essential, practical command knowledge.
Learn how the terminal uses text-based commands to control your operating system, enabling file management, program execution, and task automation for developers, admins, and power users.
Use the print working directory (pwd) command to reveal your current directory’s full path in the terminal. This helps you locate your position in the file system before navigating directories.
Learn how the ls command lists files and folders in the current directory, use pwd to locate yourself, and prepare to open, navigate, move, delete, or run scripts.
Master the change directory command (cd) to move into folders, navigate between directories, and return to the previous directory using two full stops, enabling efficient terminal navigation.
Learn to use the make directory command to create a new directory in the working directory and then navigate into it with the change directory command to organize your workspace.
Navigate to the target folder with the change directory command, then run the remove directory command to delete the specified directory from the current working directory.
Cybersecurity is essential for every organization in today’s digital age. The ISACA Cybersecurity Fundamentals Certificate provides a strong foundation in cybersecurity principles, equipping you with the knowledge and skills to protect digital assets, respond to threats, and support a secure IT environment. This course covers four key domains, offering a structured approach to cybersecurity concepts, best practices, and industry standards:
Domain 1 - Securing Assets (35%) - Protecting critical assets is at the core of cybersecurity. This domain explores asset classification, data protection, and identity and access management (IAM). You’ll learn how to implement security controls to safeguard sensitive information, prevent unauthorized access, and mitigate risks associated with physical and digital assets.
Domain 2 - Information Security Fundamentals (27%) - A strong understanding of security fundamentals is essential for any cybersecurity professional. This domain covers the principles of confidentiality, integrity, and availability (CIA), encryption basics, security governance, and risk management. You’ll also gain insights into industry standards and compliance frameworks such as ISO 27001, NIST, and GDPR.
Domain 3 - Security Operations and Response (20%) - Cybersecurity is an ongoing process that requires constant monitoring and quick response to incidents. This domain covers security operations, incident detection, log management, and vulnerability assessments. You’ll also learn how to implement incident response procedures to effectively contain and mitigate security breaches.
Domain 4 - Threat Landscape (18%) - Understanding the evolving threat landscape is crucial for building resilient security strategies. This domain examines common cyber threats, attack vectors, and threat actors. Topics include malware, phishing, ransomware, social engineering, and emerging threats targeting cloud and IoT environments.
This course provides a comprehensive introduction to cybersecurity, making it ideal for individuals looking to start a career in cybersecurity or enhance their IT security knowledge. The ISACA Cybersecurity Fundamentals Certificate is a valuable credential for anyone interested in safeguarding digital environments and mitigating cyber risks.
Please Note: This course was independently developed and are not affiliated with, endorsed by, or sponsored by ISACA—the organization that administers the official certification. Our materials are intended solely for educational and preparatory purposes.