CYS401: Fundamentals of Cyber Security
Definition: Cyber security is the protection of internet-connected systems, including hardware, software, and data, from cyberattacks.
Remember: Cyber security is not just about technology - it involves People, Processes, and Technology working together!
The foundation of information security rests on three critical pillars:
Preventing disclosure to unauthorized individuals or systems.
Ensuring data is accurate, complete, and authorized.
Ensuring authorized users can access information when needed.
Question: While a breach of confidentiality always results in a breach of ownership, a breach of ownership does not always result in a breach of confidentiality. Is this correct?
Answer: Yes! If someone reads your confidential data (breach of confidentiality), they now possess it (breach of ownership). But if someone steals encrypted data (breach of ownership), they may not be able to read it (no breach of confidentiality).
Beyond the CIA triad, consider these important characteristics:
Free from errors and meets user expectations
Genuine and original, not a reproduction
Valuable and useful for its intended purpose
Ownership or control of information
Most difficult to secure due to bugs and vulnerabilities
Physical technology requiring locks and access controls
Most valuable asset and main target of attacks
Often the weakest link - requires training and awareness
Written instructions that must be protected
People are often considered the weakest component in an IS environment. This is why security awareness training is crucial!
A three-dimensional model showing the interconnections among different information security factors:
Cyber security aims to build multiple layers of protection. Each layer provides a barrier against different types of threats:
Q: Defense in depth is used to provide a protective multilayer barrier against various forms of attack.
A: TRUE - This is the fundamental principle of defense in depth!
Understanding the difference between traditional System Development Life Cycle and Security-focused SDLC:
SecSDLC identifies specific threats and creates specific controls to counter those threats at EVERY phase, not just as an afterthought!
Note: Firewalls primarily control network traffic, not virus detection!
Can I Access? - Think of it as a question about your data: