0% found this document useful (0 votes)
3 views2 pages

NDEv1 Module01 Notes

Network security fundamentals focus on protecting information and systems from unauthorized access and disruptions through five key pillars: Confidentiality, Integrity, Availability, Authentication, and Nonrepudiation (CIANA). It emphasizes the importance of layered controls to mitigate risks from various threats, including social engineering and malware. Secure communication protocols like TLS and IPsec are essential for maintaining data integrity and confidentiality during transmission.

Uploaded by

al pacino
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views2 pages

NDEv1 Module01 Notes

Network security fundamentals focus on protecting information and systems from unauthorized access and disruptions through five key pillars: Confidentiality, Integrity, Availability, Authentication, and Nonrepudiation (CIANA). It emphasizes the importance of layered controls to mitigate risks from various threats, including social engineering and malware. Secure communication protocols like TLS and IPsec are essential for maintaining data integrity and confidentiality during transmission.

Uploaded by

al pacino
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module 01. Network Security Fundamentals.

Cornell Notes
High Level Overview
Network defense protects information and systems from unauthorized access. Misuse. Modification.
Service disruption.
Five pillars guide every decision. Confidentiality. Integrity. Availability. Authentication. Nonrepudiation.
Threats target people. Process. Technology. Use layered controls to reduce risk and impact.
Secure communication protects data in motion through encryption. Integrity checks. Strong identity proof.

Cues for Review


Key Points and Cues

CIA plus AN. Five pillars.

Threat types and attack surface.

Risk. Vulnerability. Threat. Impact.

Security protocols. HTTPS. TLS. IPsec.

Defense in depth idea.

Main Notes
Core Principles
Confidentiality means only authorized parties can see data. Use encryption and access control.
bullet
Integrity means data is accurate and complete. Use hashing. Signatures. Change control.
bullet
Availability means systems and data are ready when needed. Use redundancy. Backups. Monitoring.
bullet
Authentication verifies identity. Nonrepudiation proves an action was performed by a specific party.
bullet

Risk Language
Asset is something you value. Threat is anything that can cause harm.
bullet
Vulnerability is a weakness. Likelihood times Impact produces risk.
bullet
Reduce risk by avoiding. Transferring. Mitigating. Or accepting with justification.
bullet

Common Attacks
Social engineering. Phishing. Pretexting. Tailgating. Focus on people.
bullet
Malware. Virus. Worm. Trojan. Ransomware. Use least privilege. Patching. Application control.
bullet
Network attacks. Sniffing. Spoofing. Man in the middle. DoS. DDoS. Use segmentation and filtering.
bullet

Secure Communication
Use TLS to provide confidentiality and integrity for web traffic.
bullet
Use IPsec to secure IP packets between hosts or sites.
bullet
Prefer modern cipher suites. Disable weak protocols. Enforce certificate validation.
bullet

Defense in Depth
Layer preventive. Detective. Corrective controls.
bullet
Combine policies. Training. Physical measures. And technical safeguards.
bullet
No single control is perfect. Multiple layers reduce total risk.
bullet

Active Recall. Test Yourself


1 List the five pillars and define each in one short sentence.
2 Explain the difference between a threat and a vulnerability.
3 Give two ways to improve availability for a critical service.
4 Name three social engineering tactics and a countermeasure for each.
5 Why do we layer controls instead of trusting one control.

Summary
Use CIANA to frame every security decision. Protect data confidentiality. Maintain integrity. Keep
services available. Prove identity. Record actions.

Think in layers. Train people. Standardize process. Harden technology. Measure risk and address
the highest impact items first.

You might also like