Module 5: Information
and Computer Security
Prepared By: April 2026
Zerihun O.
Created By AI
01 Understanding Computer Security Threats
Contents 02 Implementing Security Strategies
03 Promoting Safe and Ethical Use of ICT
PART 01
Understanding Computer
Security Threats
Learning Objectives for Threats
Understand Attack Mechanisms
Define and Categorize Threats
This section explains how malware,
Students will learn to define and ransomware, and social engineering
categorize common computer security work. Understanding these mechanisms
threats, including malware, ransomware, helps educators and students recognize
and social engineering. This foundational the tactics used by attackers to
knowledge is crucial for identifying and compromise systems and steal data.
mitigating risks in educational
environments. Explain Data Breach Impact
Identify Warning Signs The objective is to explain the impact of
Learners will identify the warning signs of data breaches on individuals and
a digital attack, such as sudden system organizations, including loss of trust, legal
slowdowns, missing files, or suspicious issues, and privacy violations. This
pop-ups. Early detection is key to highlights the real-world consequences of
preventing significant damage. security failures.
Malicious Software (Malware)
Malware Definition and Types Ransomware and Real-World
Impact
Malware is software designed to cause
harm or steal data. This includes viruses Ransomware encrypts files and demands
that corrupt files and worms that spread payment for decryption. A real-world
across school networks, posing a example is a school losing access to student
significant threat to educational IT grades and lesson plans due to a teacher
infrastructure. clicking a malicious link, demonstrating the
severe operational disruption.
Hacking the Human: Social Engineering
Social Engineering Tactics Phishing and Warning Signs
Social engineering tricks people into breaking Phishing involves fake emails pretending to be
normal security procedures. Hackers use this trusted sources, aiming to steal passwords or
method to bypass technical defenses by deliver malware. Warning signs include urgent
exploiting human psychology, making it a language, unexpected attachments, and
prevalent threat in schools. mismatched email addresses, which educators
should teach students to recognize.
Data Breaches
A data breach occurs when confidential data is exposed to unauthorized
Definition and
people. Causes include weak passwords, stolen laptops, or targeted hacking,
Causes
which can happen even without advanced technical attacks.
Data breaches in schools can expose student medical records, addresses,
Impact on and staff financial information. This leads to severe loss of trust, legal
Schools trouble, and risks to student privacy, emphasizing the need for robust
security measures.
5.1 Review Questions
01 02
Key Differences and Manipulation
Scenario Analysis
The main difference between a virus and In the scenario, the warning sign is the use of
ransomware is that viruses' corrupt files, "k0tebe" instead of "otebe" in the email
address, a classic phishing trick called
while ransomware locks them for
typosquatting. This teaches students to
ransom. Phishing emails manipulate
scrutinize sender details carefully.
users by creating urgency and mimicking
trusted sources to steal credentials.
PART 02
Implementing Security
Strategies
Learning Objectives for Strategies
01 02
Authentication and System Defenses Data Backup and Security Routines
Apply rules for creating strong passwords and using Implement the 3-2-1 data backup rule and establish
Multi-Factor Authentication (MFA). Understand the role a step-by-step security routine for school devices.
of system defenses like firewalls, antivirus, and updates These practices ensure data resilience and consistent
in protecting school devices. protection against threats.
Securing Your Identity
Strong Passwords and Practical Authentication Tips
MFA
Length beats complexity in passwords; a long
Use passphrases—long sentences with mixed phrase is harder to crack than a short, complex
symbols and numbers—and never reuse word. Enabling MFA ensures that even if a
passwords. Multi-Factor Authentication password is stolen, attackers cannot access
requires two proofs of identity: something accounts without the second factor.
you know (password) and something you
have (phone code), blocking 99% of
automated hacking attempts.
Defending the Device
System Defenses Overview
Firewalls block unauthorized internet traffic, while antivirus
software scans for and removes known malware. These are
essential layers of defense for any school network or device.
Importance of Software Updates
Software updates patch critical security holes that hackers
exploit. Ignoring updates is like leaving a broken window unfixed.
Always set school lab computers to update automatically to
maintain security.
Data Preservation
Encryption and the 3-2-1 Rule
Encryption scrambles data so it's unreadable without the
correct password. The 3-2-1 backup rule involves 3 total copies,
2 different storage types (e.g., hard drive and USB), and 1 offsite
copy (e.g., cloud storage) to ensure data recovery.
Backup Strategy Importance
Backups are the only hope against ransomware or disasters like
floods. The 3-2-1 rule guarantees that no single event can wipe
out all lesson plans and student records, providing critical
resilience.
5.2 Review Questions
Password and Update Security
A passphrase is better than a complex 8-character password
because its length makes it harder for computers to crack. MFA
stands for Multi-Factor Authentication, requiring two proofs of
identity to access accounts.
Scenario Analysis
The secure choice when a computer asks to restart for an OS
update is to install it immediately. Delaying updates leaves the
computer vulnerable to recently discovered exploits, increasing
security risks.
PART 03
Promoting Safe and
Ethical Use of ICT
Learning Objectives for Ethics
Intellectual Property and Cyberbullying
Address intellectual property, plagiarism, and privacy
Digital Citizenship and Policies issues. Identify strategies to prevent cyberbullying,
Define digital citizenship and its role in education, fostering a respectful and safe digital environment
explaining the importance of Acceptable Use for students.
Policies (AUPs). These frameworks guide
responsible technology use in schools.
The Rules of the Digital Road
01 02
Digital Citizenship and AUPs Importance of AUPs
Digital citizenship involves using technology AUPs establish clear boundaries and
responsibly, safely, and respectfully. Acceptable consequences for misbehavior, such as
Use Policies (AUPs) are formal contracts signed bypassing web filters. They protect both the
by students and parents, outlining allowed and school and the student, ensuring that school
forbidden activities on school devices. computers are used for education, not gaming
or harassment.
Respecting Ideas and Privacy
Intellectual Property and Plagiarism
Intellectual Property (IP) means that content on the internet is
not necessarily free to use. Plagiarism involves copying
someone else's digital work and claiming it as your own,
which is a major issue in schools.
Privacy Protection
Never share classmates' photos, addresses, or personal data
without consent. Taking and posting photos of classmates
without permission violates their digital privacy, emphasizing
the need for respect and consent.
Cyberbullying Prevention
Cyberbullying Definition and Challenges
Cyberbullying uses digital platforms to harass, humiliate, or
threaten peers. It happens 24/7, spreads rapidly, and
perpetrators often hide behind anonymous accounts, making
it a persistent challenge.
Educator's Role in Prevention
Educators must foster a culture of reporting and teach
empathy by asking, "Would you say this to their face?"
Training students to be "upstanders" who report cyberbullying
safely to a trusted teacher is essential.
5.3 Review Questions
01 Policy and Bullying Differences 02 Ethical Scenario Analysis
An Acceptable Use Policy (AUP) is a formal contract If a student finds a teacher's password on a sticky note, the
outlining allowed and forbidden activities on school ethical response is to not use it and inform the teacher
devices. Cyberbullying differs from traditional bullying immediately. This allows the teacher to change the
by occurring 24/7 online and spreading rapidly through password and learn to secure credentials properly,
digital platforms. embodying digital citizenship.
Thank you