Section 2
Cybersecurity Introduction
What is Cybersecurity?
Cybersecurity is the combination of people, processes, and technology that come
together to protect organizations, computer systems, networks, and individuals
from the theft or damage of hardware, software, or any type of data from
disruption, misdirection, and corruption.
CIA Triangle
(CIA Triad)
Confidentiality Integrity Availability
Where is Cybersecurity Implemented?
Cybersecurity Implementations
• Cybersecurity Forms
• A process
• A strategy
• A service
• A product or technology
• A skill
• A program
• More
Cybersecurity Domains
Cybersecurity Domains
A cybersecurity domain relates to the overall definition, goal, and mission of
cybersecurity… To reduce a set of risks posed to a business and how this will impact
business operations.
Cybersecurity Domains
• Security Architecture
• Risk Assessment
• Threat Intelligence
• Governance, Risk, and Compliance (GRC)
• Security Operations
• Physical Security
Security Architecture
• Unified security design focused on setting security principles, methods, and
models designed to align with business and its corresponding security objectives.
• Considers building a secure system by design from the ground up.
Risk Assessment
• Identifying and analyzing potential hazards which could negatively impact
business processes, environments, individuals, assets and more.
• Used to identify, estimate, and prioritize risks.
• Considers monetary gains and losses of businesses.
Threat Intelligence
• Evaluation and collection of information about cyber threats and threat actors.
• This information can be used to prevent losses against an organization and
mitigate harmful events.
• Collection of various sources of information: social media, human, technical,
deep and dark web, more.
• Provides context into who is attacking an organization, motivation behind,
capabilities, and how to identify them (IoC).
Governance, Risk & Compliance (GRC)
• GRC are three facets aimed to assure an organization meets objectives, while
maintaining integrity and continuing business processes.
• Governance is the combination of processes executed by business directors to lead an
organization toward building goals and maintaining organizational structure.
• Risk and risk management is about predicting and managing risks which could impact the
organization from reliably achieving objectives and goals.
• Compliance is about establishing and following mandatory laws and regulations in
addition to following voluntary company policies, procedures, guidelines, and standards.
Security Operations
• The day-to-day security activities.
• Centralized unit dealing with organizational and technical security issues.
• Often in the form of a Security Operations Center (SOC).
• Concerned with protecting the daily functions of the business network.
Physical Security
• Considered with protecting and dealing with physical threats.
• Protection of personnel, controlling who and where has access to hardware,
software, networks, and data.
• Considers protection from natural disaster such as fire, flood, weather conditions.