
So, you want to become a Cybersecurity Specialist... This brief tutorial is design to give the novice some insight into the career field we call "Cybersecurity". It is a precursor to the Keep Cyber Simple Fundamentals Course.
This lesson provide an overview of of the entire course. We also discuss that knowing Why is paramount to knowing How. We also explain the learning approach of these lessons. "Strategic Vision - Tactical Implementation - Operational Execution”
Explore risk as the likelihood of a threat exploiting a vulnerability to impact valued assets, and learn how vulnerabilities, threats, threat agents, exposure, and countermeasures shape cybersecurity.
Review cybersecurity fundamentals and risk management with the CI triad, access control models (mandatory, discretionary, role-based), and account provisioning and management.
Explore access attacks in cyber security fundamentals, showing how attackers exploit vulnerabilities via social engineering, phishing, and reconnaissance using tools like whois, nslookup, and packet sniffers.
Explore how input, processing, output, and storage power a secure, layered computer design with hardware, the OS model, virtualization, and data protection.
Review computer hardware, memory and storage, operating systems, virtualization, and cloud service models (software as a service, platform as a service, infrastructure as a service) with OSI and TCP/IP concepts.
Explore how cyber security policy guides risk assessment and information categorization by confidentiality, integrity, and availability, to selecting and continuously monitoring controls under the risk management framework.
Identify external and internal cybersecurity roles and responsibilities, from authorized officials to information system security officers, and explain how they collaborate to assess risks, authorize operations, and maintain security documentation.
This module introduces six-step risk management framework, covering categorization, selecting controls, implementing controls, and explains risk as the likelihood of a threat exploiting a vulnerability with business impacts.
This lecture maps the six-step risk management framework to a home computer scenario, teaching categorization, choosing and implementing controls to protect confidentiality, integrity, and availability of family information.
This is a fun and probably a different type of cybersecurity course that you typically see in online venues.
These lessons are designed for individuals with little to no experience in Technology or Cybersecurity. I meet so many intelligent individuals every day who would do great in Information Technology or Cybersecurity career fields. However, they are shell-shocked by all the geeky terminology and jargon we use.
My goal in developing these series of courses is to use common analogies to explain more complex skills. Hence, the slogan you will see in these lessons "There is nothing New under the Sun"
I employ several hilarious analogies and vignettes such as "Buying my parents a new computer" to show how the 6-step Risk Management Framework (RMF) is used to "Aida's Kitchen" which explains the inter-workings of computer hardware. Managing risk is something that every human on the plant does daily. Cybersecurity is not just a bunch of technical jargon; it is really a time-tested method of managing security risk.
If you are looking for someone with an accent teaching a lot of high-tech jargon, this is NOT the course for you. However, if you are looking for a course to help you understand the core tenets of Cybersecurity, then I think you will enjoy the journey as we Keep Cyber Simple!