Cybersecurity Fundamentals Course Guide
Cybersecurity Fundamentals Course Guide
Cybersecurity Fundamentals
6302/36 weeks
Table of Contents
Acknowledgments ......................................................................................................................................... 1
Course Description ........................................................................................................................................ 2
Task Essentials Table..................................................................................................................................... 2
Curriculum Framework ................................................................................................................................. 4
Understanding Cyber Threats and Vulnerabilities....................................................................................... 16
Exploring Ethics as it Relates to Cybersecurity........................................................................................... 23
Exploring Data Privacy ................................................................................................................................ 27
Examining Data Security as it Relates to Cybersecurity ............................................................................. 30
Programming as a Component of Cybersecurity ......................................................................................... 40
Exploring Cybersecurity Implications for Current and Emerging Technologies ........................................ 44
Exploring Cybersecurity Careers ................................................................................................................. 45
Preparing for Industry Certification ............................................................................................................. 47
SOL Correlation by Task ............................................................................................................................. 49
Teacher Resources ....................................................................................................................................... 53
Appendix: Credentials, Course Sequences, and Career Cluster Information .............................................. 63
Acknowledgments
The components of this instructional framework were developed by the following curriculum
development panelists:
Correlations to the Virginia Standards of Learning were reviewed and updated by the following:
1
The framework was edited and produced by the CTE Resource Center:
Judith Sams, Specialist, Business and Information Technology Education and Related Clusters
Dr. J. Anthony Williams, Curriculum and Instruction Coordinator
Dr. David S. Eshelman, Director, Workforce Development and Initiatives
George R. Willcox, Director, Operations and Accountability
Office of Career, Technical, and Adult Education
Virginia Department of Education
Copyright © 2021
Course Description
Suggested Grade Level: 9 or 10 or 11 or 12
Cybersecurity affects every individual, organization, and nation. This course focuses on the
evolving and pervasive technological environment with an emphasis on securing personal,
organizational, and national information. Students will be introduced to the principles of
cybersecurity, explore emerging technologies, examine threats and protective measures, and
investigate the diverse high-skill, high-wage, and high-demand career opportunities in the field
of cybersecurity. Exciting opportunities will be presented to use interactive current resources in
the study of cybersecurity such as Virginia Cyber Range, Virginia Space Grant Consortium, and
[Link]. Students will have the opportunity to prepare for success on related industry
certifications aligned to the course content.
2
3
Curriculum Framework
Exploring Cybersecurity Fundamentals
Task Number 39
Describe cybersecurity.
Definition
Description should state that cybersecurity is the protection of information and data from risks
associated with threats, attacks, hazards, or physical damage. Risks may include, but are not
limited to
• information systems (e.g., networks, hardware, software)
• the human element
• physical elements
from risks associated with threats, attacks, hazards, or physical damage.
4
Networking Infrastructure
Task Number 40
Describe the critical factors of information assurance.
Definition
Description should include
• explaining that the CIA triad model provides the baseline standard of evaluating and
implementing information security measures on any system
• stating that each component in the CIA triad has designated goals that provide distinct
requirements, and that each goal provides an essential component of information security
measures
• identifying the goals within the CIA triad and defining the terms as they apply to
cybersecurity
o confidentiality―ensures that data are only accessed by authorized person(s)
through security measures such as usernames and passwords and access control
lists (ACL)
o integrity―ensures the data are trusted. This means data must be guarded against
unauthorized changes; methods of ensuring integrity include data permissions and
encryption
o availability―provides solutions to ensure that systems can be accessed when
requested; this includes providing deploying system protections and proper
hardware maintenance and system patching.
Task Number 41
Define vulnerability and risk.
Definition
Definition should state that
5
• vulnerability refers to a flaw in a system that can leave it open to attack; may also refer to
any type of weakness in a computer system, in a set of procedures, or in anything that
leaves information security exposed to a threat.*
• risk is the likelihood that a vulnerability will occur and that a loss occurs if that
vulnerability is exploited.
*Technopedia ([Link]/definition/13484/vulnerability).
Task Number 42
Explain why organizations need to manage risk.
Definition
Explanation should include the following:
Because all threats cannot be completely eliminated, organizations must address responses to
threats and plans for continuous business operations.
Networking Infrastructure
Task Number 43
Identify the concepts of cybersecurity risk management.
Definition
Identification should include
Task Number 44
Describe cybersecurity threats to an organization.
Definition
Description should include
• understanding that an action might exploit a vulnerability to breach security and cause
potential harm
• understanding that threats come from many sources
o email
o social engineering
o insider threats
o network threats
7
Teacher resource:
[Link] Cyber Business Module: How Businesses Secure Information,
([Link]
FBLA Competitive Events and Activities Areas
Business Knowledge and Skills
Business Ethics
Business Law
Cyber Security
E-business
Healthcare Administration
Introduction to Information Technology
Management Decision Making
Management Information Systems
Network Design
Networking Infrastructure
Website Design
Task Number 45
Describe national and industry standards and regulations
that relate to cybersecurity.
Definition
Description should include, but not be limited to, the following:
• Standards and regulations are determined based on the data each stores.
• Standards―a set of best practices that have been created to guide an organization’s
policies, procedures, and practices, rather than requirements to adhere to specific rules.
For example, Payment Card Industry Data Security Standard (PCI DSS) is an information
security standard for organizations that accept payment cards.
• Regulations―requirements by a government agency that must be followed. For example,
in the healthcare industry, any system or user that has access to personal health
information must follow the regulations set forth in the Health Insurance Portability and
Accountability Act (HIPAA).
8
Task Number 46
Describe the cyberattack surface of various organizations.
Definition
Description should include a definition of threat modeling and the concepts that
• the attack surface includes all areas of an organization that can be penetrated or
threatened
• companies may have differing levels of vulnerability due to their integration of
technology.
For example, a company that processes payments via an Internet site increases the vulnerability
of threats against the payment processing system from attackers anywhere in the world. A
company that does not collect information via the Internet would have much less vulnerability
from that attack avenue.
Teacher resource:
[Link] Cyber Business Module: How Businesses Secure Information,
([Link]
FBLA Competitive Events and Activities Areas
Business Knowledge and Skills
Business Ethics
Business Law
Cyber Security
E-business
Healthcare Administration
Introduction to Information Technology
Management Decision Making
Management Information Systems
Network Design
Networking Infrastructure
Website Design
Task Number 47
Analyze risks affecting critical infrastructure.
9
Definition
Analysis should include
Teacher resource:
Critical Infrastructure Sectors, Cybersecurity and Infrastructure Security Agency
([Link]
Task Number 48
Describe computer components.
Definition
Description should include
• case
10
• motherboard
• central processing unit (CPU)
• random access memory (RAM)
• hard drive
• power supply
• ports.
Task Number 49
Describe a network.
Definition
Description should include identifying
Task Number 50
Describe a wired network.
Definition
Description should include
• defining wired network as a network in which all components are connected with fiber
optic cables most common wired networks use cables connecting a computer to Ethernet
ports on a network router
11
Task Number 51
Describe a wireless network.
Definition
Description should include
• defining wireless network as a computer network in which connections are made without
computer cables.
• Explaining the basis of wireless transmissions is radio waves (e.g., radio waves connect
devices to the Internet and to a business network and its applications)
• explaining 802.11 wireless local area network standards
• explaining authentication types.
Task Number 52
Compare wired and wireless networks.
Definition
Comparison should include
12
Task Number 53
Compare networking conceptual models.
Definition
Comparison should include the following models:
Task Number 54
Discuss services and potential vulnerabilities.
Definition
Discussion should include
13
Task Number 55
Differentiate between network types.
Definition
Differentiation may include the following:
• Local Area Networks (LAN)―a collection of computers, peripherals, and other devices
that communicate across a network (e.g., wire, fiber optic, wireless) in a single network
segment; LANs differ from Wide Area Networks (WANs) in their reliance on local
addressing schemes and their ability to operate without knowledge of neighboring
networks.
o LANs rely on local addressing and local network communications protocols (e.g.,
Address Resolution Protocol [ARP] that are the core differentiator between a
LAN and a WAN; LANs are often characterized as being small in size, such as
being contained within a room or a building.
o LANs are frequently referred to by other terms that indicate their tendency for
limited size, such as Personal Area Network (PAN), Home Area Network (HAN),
or Storage Area Network (SAN).
o LANs use addressing schemes (e.g., Media Access Control [MAC] addressing)
for communication.
• Wide Area Networks―a network of LANs; WANs are primarily focused on routing
traffic between local network segments and use technologies and protocols that differ
from those employed by LANs.
o The Internet is the most widely known example of a wide area network.
o While WANs are sometimes characterized in terms of size as having regional,
national, or global scope, the difference in the technologies used is the core
differentiator between LANs and WANs.
14
o WANs are frequently referred to by other terms that describe the scope of a
specific implementation, such as Campus Area Network (CAN), Metropolitan
Area Network (MAN), or Global Area Network (GAN).
o WANs most commonly route traffic at the network layer (i.e., layer 3), where
routing is determined based on IP addresses and the network identifier (i.e.,
subnet mask).
Task Number 56
Describe the concept of the Internet as a network of
connected systems.
Definition
Description should include
• a definition of the Internet as a global system of interconnected computer networks that
use the Internet Protocol Suite (TCP/IP) to link billions of devices worldwide.
• the concept that it is a network of networks that consists of millions of private, public,
academic, business, and government networks of local to global scope, linked by a broad
array of electronic, wireless, and optical networking technologies.
Task Number 57
Identify networking protocols.
Definition
Identification should include descriptions of
• application layers protocols
15
Task Number 58
16
Task Number 59
Describe types of cyber threats.
Definition
Description should include, but not be limited to
17
Task Number 60
Analyze types of current cyber threats.
Definition
Analysis could include, but not be limited to, areas and types of threats related to
• physical facilities
• toys
• unmanned systems
• infrastructure
• cloud computing
• mobile devices
• automobile hacking
• chip technology
• phishing attacks
• denial of service (DOS)
• distributed denial of service (DDOS)
• malware (e.g., virus, worm, botnet, ransomware)
18
• medical devices
• state-sponsored hacking.
Task Number 61
Describe the concept of malware and the techniques to
guard against it.
Definition
Description should include
Task Number 62
Identify the perpetrators of different types of malicious
hacking.
Definition
Identification should include, but not be limited to
• script kiddies―an attacker who uses tools written by other people without an
understanding or ability to write such programs themselves
• professional criminals
• spammers
• hacktivists
• state-sponsored advanced persistent threat (APT) hacking groups
• cyber warriors (i.e., members of a government agencies and military team of elite
cybersecurity professionals).
Task Number 63
Describe the characteristics of vulnerabilities.
Definition
Description should include
• defining the term vulnerability as a weakness that allows an attacker to reduce a system’s
information assurance
• understanding that a large number of vulnerabilities historically have been through flaws
in software
• describing elements that make a system vulnerable
o a system susceptibility or flaw
o attacker access to the flaw
o attacker capability to exploit the flaw
20
Teacher resource:
• Common Vulnerabilities and Exposures, ([Link]
• U.S. Department of Homeland Security,
([Link]
Task Number 64
Identify the prevention of and protections against cyber
threats.
Definition
Identification should state that preventions and protections against cyber-attacks change as the
targets, vulnerabilities, and threats change.
Identification should state that each vulnerability will have its own unique set of preventions and
protections, and should include, but not be limited to the following:
• Network protection is often the initial line of defense (e.g., authentication, firewalls, end
point protection software, intrusion detection system [IDS]/intrusion prevention system
[IPS], vulnerability scanners).
21
Task Number 65
Identify the cyber risks associated with bring your own
device (BYOD) opportunities on computer networks.
Definition
Identification should include how BYOD practices can expose a network to malware and other
threats, creating additional vulnerabilities in a number of ways, such as
22
Task Number 66
Differentiate between ethics and laws.
Definition
Differentiation should include
Task Number 67
Distinguish among types of ethical concerns.
Definition
Distinction should include
23
Teacher resource:
[Link] Cyber Society ([Link]
Task Number 68
Define cyberbullying.
Definition
Definition should include using technology (i.e., Internet, interactive and digital technologies) to
harass, embarrass, threaten, or otherwise target another person. By definition, cyberbullying
involves minors; with adults, it is cyber harassment or cyber stalking.
Task Number 69
Identify actions that constitute cyberbullying.
Definition
Identification should include
24
Business Procedures
Cyber Security
Introduction to Business Communication
Introduction to Social Media Strategies
Social Media Strategies
Task Number 70
Identify possible warning signs of someone being
cyberbullied.
Definition
Identification could include signs such as
Task Number 71
Demonstrate net etiquette (i.e., netiquette) as it relates to
cybersecurity.
Definition
Demonstration should include
25
Teacher resources:
• What Do I Need to Know about Technology? Northern Virginia Community College
([Link]
• Brooks, A. (2019, January 28). Ten Netiquette Guidelines Every Online Student Needs to
Know, Rasmussen University. [Link]
life/netiquette-guidelines-every-online-student-needs-to-know/
Task Number 72
Identify laws applicable to cybersecurity.
Definition
Identification should include, but not be limited to
26
Business Law
Cyber Security
Task Number 73
Explain the concept of “personally identifiable information.”
Definition
Explanation should include
• defining personal data, including data elements such as name, address, social security
number, telephone number, email address
• differentiating between the meaning of data and information
• defining digital footprint, including digital traces
• listing examples of digital footprints that occur in everyday life
• analyzing digital footprint examples to interpret information about individuals
• naming the types of data individuals and businesses generate.
Teacher resource:
[Link] Cyber Business Module: You are the Data, ([Link]
society/business)
FBLA Competitive Events and Activities Areas
Business Knowledge and Skills
Cyber Security
Database Design and Application
E-Business
Healthcare Administration
Introduction to Information Technology
Introduction to Social Media Strategies
Social Media Strategies
Spreadsheet Application
Website Design
Task Number 74
Explain why personal data is valuable to both an individual
and to organizations (e.g., governments, businesses) that
collect it, analyze it, and make decisions based on it.
Definition
Explanation should include
27
Teacher resource:
[Link] Cyber Business Module: You are the Data, ([Link]
society/business)
Task Number 75
Explain the techniques used to collect personal data through
social media, web tracking, and mobile devices.
Definition
Explanation should include
28
Task Number 76
Identify ways to control and protect personal data.
Definition
Identification should include
Teacher resource:
Task Number 77
29
Teacher resource:
[Link], Cyber Law Module: Your Permanent Electronic Record, ([Link]
society/law)
Task Number 78
Distinguish between data, information, and knowledge.
Definition
Distinction should include
30
Task Number 79
Identify the most common ways data is collected.
Definition
Identification should include
• defining the term data collection as the process of gathering pieces of information
o active vs. passive
o informed consent vs. no consent
• describing the types of sources where data can be collected.
Task Number 80
Identify the most common ways data can be stored.
Definition
Identification should include methodologies such as
• flat-file
• simple database structure (i.e., spreadsheet)
• relational database
• big data
• cloud storage.
31
Task Number 81
Explain the difference between data at rest, data in transit,
and data being processed.
Definition
Explanation should include
32
Task Number 82
Identify the most common ways data is used.
Definition
Identification should include how to extract specific information from stored data (e.g., data
filtering; data queries including structured query language [SQL]; data mining; data analytics).
Task Number 83
Discuss how data can be compromised, corrupted, or lost.
Definition
Discussion should include
• how vulnerabilities exist regardless of the state (e.g., data at rest, data in transit, data
being processed) of the data
• methods by which data could be compromised (e.g., corruption, loss, SQL-injection
attacks, ransomware, sabotage).
33
Task Number 84
Explain how businesses and individuals can protect
themselves against threats to their data.
Definition
Explanation should include
34
Task Number 85
Define the function of a computer operating system.
Definition
Definition should include
Task Number 86
Identify the components of an operating system.
Definition
Identification should include
• kernel
• shell
• utilities
• file system
• process management, including services
• networking.
35
Task Number 87
List types of operating systems.
Definition
Listing should include
• desktop
• server
• mobile
• network (network devices).
Task Number 88
Identify examples of widely used desktop and server
operating systems.
Definition
Identification should include
• Windows desktop operating systems (e.g., Windows 10)
• Windows servers OS (e.g., Windows Server 2019)
• Apple operating systems (e.g., iOS, MacOS)
• Linux operating systems (e.g., Kali, Ubuntu, CentOS).
Task Number 89
Evaluate the potential vulnerabilities, threats, and common
exploits to an operating system.
36
Definition
Evaluation should include the flaws to an operating system and the current and emerging threats,
such as viruses, dynamic-link library (DLL) injection, or zero-day vulnerability.
Task Number 90
Identify best practices for protecting operating systems.
Definition
Identification should include patch management, application updates, and OS hardening.
• authentication policy
• access control (i.e., rights and permissions)
• audit policy.
37
Networking Infrastructures
Task Number 92
Describe security and auditing logs.
Definition
Description should include the types of logs, including a definition and purpose for each.
Task Number 93
Describe the role of a system backup.
Definition
Description should include
Task Number 94
Define virtualization technology.
Definition
Definition should include, but not be limited to
38
Task Number 95
Identify advantages and disadvantages of using virtual
machines.
Definition
Identification of advantages should include, but not be limited to
• reduced cost in
o capital expenditure
o energy expenditure
o operational expenditure
• consolidation of resources
o physical server consolidation
o management of server consolidation
o many applications on each server
o multiple operating systems can exist, isolated from each other, on the same virtual
server
• isolation
o if one virtual server has a software failure, others are not affected
o upgrades and changes can be made only where required.
• efficiency
o virtual machines are not as efficient in accessing hardware as a real machine
o multiple virtual machines running on a host computer may introduce unstable
performance to the host on each virtual machine and thus affect the other virtual
machine’s application
• cost
39
o software for virtual machines may cost more due to the expense of virtualization
software
o additional software management tools may be required
• compatibility (e.g., not all servers and applications are virtualization-friendly)
• complex root-cause analysis.
Programming as a Component of
Cybersecurity
Task Number 96
Identify representation of data at lowest levels.
Definition
Identification should include
• recognizing binary data
• recognizing hexadecimal data, and its relationship to binary data
• recognizing the representation of data in other common numbering systems such as Octal
and Base64.
Task Number 97
Define programming in the context of cybersecurity.
Definition
Definition should include
40
Task Number 98
Differentiate between computer programming languages.
Definition
Differentiation should include
• compiled languages
• interpreted languages (i.e., scripting)
• markup languages.
Task Number 99
Describe Python.
Definition
Description should include
• using programming to walk through designated lessons
• creating a basic program
41
42
Definition
Evaluation should include the concept that other programmers can change coding, scripts, or
algorithms in any computer program. Evaluation also should include a discussion of flaws in
software that can lead to vulnerabilities, such as
• buffer overflow
• broken authentication and session management
• injection vulnerabilities
• input validation
• privilege confusion.
• input validation
• data sanitization
• secure design principle.
43
44
Teacher resource:
Breaking the Code on a Career in Cybersecurity, Virginia Space Grant Consortium
([Link]
45
• online resources that specialize in providing this type of information (e.g., O*Net, Bureau
of Labor Statistics’ Occupational Outlook Handbook, Virginia Education Wizard,
CyberSeek)
• common pathways based on industry requirements (i.e., internships, community college,
or four-year university)
• academic goals (e.g., strong mathematics skills)
• career and technical education goals (i.e., industry certifications and licensure)
• postsecondary options (i.e., internships, community college, technical institutes, or four-
year universities).
46
47
• a list of industry certifications related to the Cybersecurity Fundamentals course and the
process and requirements for obtaining the certifications from official websites of the
testing organization or vendor
• materials from publishers that have developed practice materials and tests based on
information from the testing organization/provider
• information from certified instructors or industry-certified professionals.
Demonstration should include obtaining and successfully completing practice examinations for
selected certifications related to the course (e.g., practice questions similar to those on
certification exams). Practice examinations may be obtained from provider sites and/or materials
from publishers.
48
49
Analyze risks affecting critical infrastructure. English: 9.3, 9.5, 10.3, 10.5, 11.3, 11.5,
12.3, 12.5
Discuss services and potential vulnerabilities. English: 9.3, 9.5, 10.3, 10.5, 11.3, 11.5,
12.3, 12.5
Differentiate between network types. English: 9.5, 10.5, 11.5, 12.5
Describe the concept of the Internet as a network English: 9.3, 9.5, 10.3, 10.5, 11.3, 11.5,
of connected systems. 12.3, 12.5
Identify the cyber risks associated with bring your English: 9.5, 10.5, 11.5, 12.5
own device (BYOD) opportunities on computer
networks. Social Studies: WG 17; WHII 14; VUS 14;
Govt 7, 8, 9, 12, 15
Differentiate between ethics and laws. English: 9.5, 10.5, 11.5, 12.5
50
Distinguish among types of ethical concerns. English: 9.5, 10.5, 11.5, 12.5
Explain the techniques used to collect personal English: 9.3, 9.5, 10.3, 10.5, 11.3, 11.5,
data through social media, web tracking, and 12.3, 12.5
mobile devices.
Social Studies: WG 17; WHII 14; VUS 14;
Govt 7, 8, 9, 12, 15
Identify ways to control and protect personal data. English: 9.5, 10.5, 11.5, 12.5
51
Mathematics: COM.10
Description security and privacy implications of English: 9.5, 10.5, 11.5, 12.5
ubiquitous computing.
Research career opportunities for cybersecurity English: 9.1, 10.1, 11.1, 12.1
professionals.
Examine the Career Clusters affected by current English: 9.8, 10.8, 11.8, 12.8
and emerging technology.
Social Studies: WG 17; WHII 14: VUS 14:
Govt 7, 8, 9, 12, 15
Identify the educational pathways for emerging English: 9.5, 9.8, 10.5, 10.8, 11.5, 11.8,
cybersecurity professionals. 12.5, 12.8
52
12.5, 12.8
Teacher Resources
Instructional Scenarios
Risk/Vulnerabilities/Management, Oh My!
Duty/Concept Area(s): Exploring Cybersecurity Fundamentals
Scenario:
You have been hired by the Trigon Corporation to create a series of presentations on
security risks. The president wants his employees to be knowledgeable of the types of
cybersecurity threats to the company and its employees.
Big Question:
What are risk and vulnerabilities, and how does a company manage them?
Focused Questions:
1 What is the definition of risk?
2 What is the definition of vulnerability?
3 Why do organizations need to manage risk?
4 Why are the basic concepts of cybersecurity risk management?
Project-Based Assessment:
Read the following paper: [Link]
room/whitepapers/auditing/introduction-information-system-risk-management-1204
Create a Power Point to present to the users of Trigon. The Power Point should include an
appropriate background, pictures, and the following information on the slides:
Introduction
•
Definition of risk and an example.
•
Definition of vulnerability and two examples.
•
Explanation of why users need to manage risk.
•
Explanation of the concepts of managing risk. A slide should be done for each of these
•
concepts and examples of where each might be used should be provided (these are the
same as in economics and personal finance):
o Risk Mitigation
o Risk Transfer
o Risk Avoidance
o Risk Acceptance
Resources:
53
Scenario:
You have been hired by a large bank in Virginia. They have asked you to detail what
threats they might expect to their network and business. Specifically, they would like to
know who might attack their network and how the attack would occur.
Big Question:
Can you describe the cybersecurity threats to an organization?
Focused Questions:
1 Who are the threat actors?
2 What are the attack types?
3 What types of malware are out there?
Project-Based Assessment:
• [Link]
o Section 1.1 – Malware (all)
o Section 1.2 – Attack Types (all)
o Section 1.3 – Threat Actors
A bank with a large footprint in the Commonwealth of Virginia is potentially at risk for cyber
threats.
You have been asked to write a report that details the following:
• Who are the top two threat actors?
o Why are they the most concerning?
o What can they affect within the network?
• What are the top five attacks the bank faces regarding its internal network?
o How do they work?
o Why are they the top ones?
o How would they affect the business/network?
• What are the top two attacks to the bank’s web-facing systems?
o How do they work?
o What makes these attacks the most prevalent?
o How would they affect the business/network?
For this report, follow APA format and cite a minimum of five other references.
Resources:
• World’s Biggest Data Breaches & Hacks, Information is Beautiful
• [Link], Instructure
• Open Web Application Security Project (OWASP) Top Ten, OWASP Foundation
We Have Standards?
Duty/Concept Area(s): Discuss national or industry standards/regulations that relate to
cybersecurity.
Scenario:
54
You would like to leave your position at the hospital to enter the field of education or
pursue a position at the Department of Defense. How do you research the differences in
regulations regarding cybersecurity in this field?
Big Question:
What are the industry standards/regulations that relate to cybersecurity?
Focused Questions:
1 What is PCI DSS?
2 What is FERPA?
3 What is HIPPA?
4 What is GDPR?
5 What is NIST?
6 What is ISO?
Project-Based Assessment:
Arrange students into groups of two or three, or make this an individual assignment. Research
regulations and frameworks for security. Choose a total of ten different frameworks and provide
the following information for each in chart format:
Resources:
• Infosecurity Magazine, Infosecurity Group
• 23 Top Cybersecurity Frameworks, CyberExperts
• Cybersecurity Frameworks 101 – The Complete Guide, Prey Project
Scenario:
You have been hired by a contractor from the Department of Defense to review their risk
factors and make suggestions on how to decrease their attack surface. They have
• communications (wired/wireless)
• connections to the Internet for employees to use
• facilities within five miles of each other
• door locks as the only form of physical security into the building
• credit card payments accepted over the web.
Big Question:
Can you describe what cybersecurity is and what it is exactly that businesses want to
protect?
Focused Questions:
1 What is important for companies to protect?
2 What are the differences in the definition of cybersecurity?
3 Why is cybersecurity important?
Project-Based Assessment:
Research how to reduce your attack surface, then review the scenario. Determine what
attack areas are wide open, which ones you would fix, and how. Share these with your
fellow students in a discussion.
Resources:
• [Link] Cyber Business Module: How Businesses Secure Information
55
Scenario:
You have been hired by a company to make a presentation to the Department of
Homeland Security about a specific piece of critical infrastructure.
Big Question:
What are the critical infrastructure areas found in cybersecurity? How can they be
threatened, and how can they be protected?
Focused Questions:
1 What threatens our critical infrastructure?
2 What are the 16 critical infrastructure areas?
3 How are threats evolving?
4 How do those threats relate to these infrastructure areas?
Project-Based Assessment:
Arrange students into research groups of two or three to gather required information for the
presentation.
56
57
Resources:
• Cybersecurity and Infrastructure Security Agency
• Critical Infrastructure Security, Department of Homeland Security
• [Link], Cyber Innovation Center 2020
• 2017 Infrastructure Report Card, American Society of Civil Engineers
Scenario:
You and your partners are developing a Blue Team defense system for a personal
residence home. After reviewing the home plan, the team realizes that there are physical
and digital weaknesses that need to be secured to protect the property, personal items,
important documents, and digital access.
The home owners requested that the following be addressed and implemented:
• How is unauthorized access gained to the home and the home network?
• How will the home office be secured?
• Will the homeowners have access to necessary protections if they are on a budget?
• Can their home and data be protected in a way that prevents anyone from being
harmed?
Big Question:
How can businesses, residences, and users protect themselves from both physical & cyber
threats?
58
Focused Questions:
1. Why do we need to protect our system?
2. How can someone gain unauthorized access to a physical location and network?
3. Can you predict and prevent all attacks?
4. Can you make anything 100 percent secure?
Project-Based Assessment:
Complete a small group activity threat modeling a home, taking on the mindset of Blue Team
to protect the home. When the activity is completed, have the groups switch plans and take
on the mindset of the Red Team to determine if there are any vulnerabilities in the plans. Use
the link in the resources to access the lessons.
Resources:
• The Security Mindset: Cybersecurity through Threat Modeling
• Open Source Security, pfSense, Electric Sheep Fencing, LLC
Scenario:
One responsibility of the department store’s security team is to monitor free Wi-Fi traffic
to make sure no one is conducting illegal activity over the store’s wireless network. In the
course of normal monitoring activities, the security team intercepts emails between two
people who are experiencing serious financial problems. The contents of these emails are
in plain text and can be easily viewed by common packet sniffing tools.
Both people have recently been laid off from their jobs. The emails include details such
as the couple’s car recently being repossessed and a pending foreclosure on their house.
While it seems unlikely that the couple will be able to pay off any future credit card bills,
the couple’s store credit account is still current and in good standing. The couple gathers
a rather large and expensive selection of products, and they tell the store clerk to charge
the items to their store credit account. The store’s management, however, has already
closed out the couple’s account based on the intercepted emails.
Big Question:
Can the store ethically intercept private conversations taking place across a network
connection that they own and provide to customers free of charge?
Focused Questions:
1. What expectation of privacy does the couple have in this situation?
2. What could the couple do to protect themselves from such unwanted scrutiny?
3. How does the store balance its obligation to prevent illegal activity across its network
with a customer’s right to privacy?
Project-Based Assessment:
Class discussion/role play illustrating obligations and rights of both the customer and the
store.
Scenario:
You have been hired to review a client's online privacy. They have been hacked, and you
are looking at their potential profile and posting issues to help them have a more secure
online experience. The client is also asking how their information can be exploited and
used by other people and companies.
Big Question:
How can users protect themselves and their data from being exploited?
59
Focused Questions:
1. What are the risks associated with posting personal information?
2. How do you protect your privacy on social media and commercial websites?
3. What kind of information is being collected on the sites, platforms, and browsers that
you use?
4. What are the benefits and risks of online tracking for users?
5. How do you protect yourself from online tracking?
Project-Based Assessment:
• In a small group, review a fictional public social media network profile. Prepare a
presentation
! reporting potential privacy issues
! offering suggestions on how to protect from online tracking from other people and
companies
! offering solutions to ensure private information is secure.
• Use the first link under Resources to access the lesson and examples of profiles for this
assessment. You may also create multiple profiles for each group to research and present.
Links have been provided below to use as projects, activities, and assessments.
Resources:
• The Invisible Machine: Big Data and You, The eQuality Project, Media Smarts
• 23 Great Lesson Plans for Internet Safety, Common Sense Media
• The Big Data Dilemma, Common Sense Media
• Debating the Privacy Line, Common Sense Media
• Privacy and Internet Life: Lesson Plan for Intermediate Classrooms, Common Sense
Media
• Privacy Badger, Electronic Frontier Foundation
Scenario:
You decide you want to purchase a Bluetooth speaker. You visit [Link] first.
When you enter “Bluetooth Speaker” into the search bar, you receive a lot of results. You
also find you can filter your criteria by
• price
• speed of shipment
• type of phones compatibility
• special features
• manufacturer
• a number of other criteria.
When you create a Google search for “Bluetooth Speaker” the results are very different,
and you can’t really filter them in the same ways. Why is this?
Big Question:
In what ways are companies able to tailor data to your specifications and interests?
Focused Questions:
1. Where is this data being stored? Is it a type of software?
2. How can the specified criteria be filtered so quickly?
3. Why do different kinds of searches vary so much?
4. Are there different ways of accessing all of this data?
Project-Based Assessment:
Create a simple relational database and design a query that will filter the data based on
user selections. It should
• Demonstrate ways in which the data could be “tainted” to cause it to not function
properly.
60
• Examine ways to make queries less exact (i.e. like or wildcard queries)
• Look at the difference between a natural language query and a SQL query.
Resources:
• [Link]
• [Link]
access-database/
• Different operating systems allow users to automatically upload files from one device to
another. Why should this be important to you?
• Looking at this scenario, what would happen if John clicks “Allow”?
• Would John still have privacy rights to his photos if they are uploaded onto his school
computer?
• Can anyone who has access to his laptop now see those photos?
• What can you do to keep your information private?
Resources:
Show App permissions - What you need to know and discuss why companies harvest
your data.
Scenario:
Susie has an Amazon Alexa device in her home, and she uses it to play her favorite music
and call her friends. Amazon Alexa is an example of an Internet of Things (IoT). What are
the pros and cons of this type of IoT?
Big Question:
What are the pros and cons of the Amazon Alexa IoT?
Focused Questions:
1 Is an IoT like Amazon Alexa always listening to you? If so, is that data stored? How
is it used?
2 Can Amazon Alexa be hacked? How? Why would someone want to hack your
Amazon Alexa?
3 How do you know if someone is dropping in on Amazon Alexa?
Project-Based Assessment:
• Have your students research the focus questions and share the information with the rest of
the class. This can be a project or a quick 15-minute exercise.
61
Resources:
• Google
• Amazon Echo Privacy - Is your information safe?
[Link]
• Optional project - Create your own IoT - full lesson plan
• [Link]
haring
62
Concentration sequences: A combination of this course and those below, equivalent to two 36-week
courses, is a concentration sequence. Students wishing to complete a specialization may take additional
courses based on their career pathways. A program completer is a student who has met the requirements
for a CTE concentration sequence and all other requirements for high school graduation or an approved
alternative education program.
Pathway Occupations
63
Pathway Occupations
Computer Support Specialist
Database Administrator
Database Analyst
Information Support Information Systems Analyst
and Services Internet Entrepreneur
Network Systems and Data Communication Analyst
Software Test Engineer
Systems Analyst
Computer Security Specialist
Computer Systems Engineer, Architect
Database Analyst
Network Systems Information Security Analyst
Network and Computer Systems Administrator
Network Architect
Network Systems and Data Communication Analyst
Systems Analyst
Applications Integrator
Computer Software Engineer
Game Designer, Programmer
Informatics Nurse Specialists
Information Security Analyst
Programming and Multimedia Artist, Animator
Software Network Systems and Data Communication Analyst
Development Programmer
Project Manager
Software Applications Engineer
Software Test Engineer
Systems Analyst
Web Developer
Applications Integrator
Computer Support Specialist
Computer Systems Engineer, Architect
Web and Digital Game Designer, Programmer
Communications Project Manager
Software Test Engineer
Systems Analyst
Web Developer
64
BYOD policies pose risks such as bypassing organizational security controls like password complexity, devices may not be regularly patched or updated, and personal devices often lack robust security software. These factors can lead to malware infections and data breaches if devices store sensitive data or connect to the organization's network .
Ethics involve moral principles guiding individual conduct, while laws are formalized rules established by authorities. In cybersecurity, ethics influence how professionals address privacy and data security, often requiring actions beyond legal obligations. Legal compliance, on the other hand, ensures adherence to established regulations and standards .
Essential components of an operating system include the kernel, which manages hardware and system processes; the shell, which interprets commands; utilities allowing system management tasks; the file system organizing data storage; and process management overseeing running services and networking .
Wired networks provide stable and secure connections using cables. They often have higher data transfer speeds and less susceptibility to interference but lack the flexibility of mobility. Wireless networks offer convenience and mobility, but they can be more vulnerable to security breaches and interference, affecting performance .
Organizations have varying levels of vulnerability based on their integration of technology. A company processing payments online increases its attack surface and is more vulnerable to global cyber threats, while a company that does not use the Internet for data collection has a reduced attack surface and lower vulnerability from online threats .
Addressing injection vulnerabilities during design and programming is critical as it prevents flaws from being introduced into production systems, where they can be exploited. Early intervention helps safeguard against data theft and system compromise by ensuring that data sent to interpreters is trusted and validated .
Risk management is crucial as it helps organizations identify, assess, and mitigate potential threats, particularly in cybersecurity. Effective risk management protects against data breaches, financial loss, and reputational damage, ensuring the organization’s resilience and compliance with legal regulations .
National and industry standards establish guidelines and best practices for cybersecurity, ensuring organizations implement effective security measures. These standards help govern how data is protected, what protocols to follow, and how to respond to incidents, thus ensuring consistent and robust security across industries .
The incapacitation or destruction of critical infrastructure, which includes sectors vital to society and the economy, can severely impact national security, economic stability, and public health and safety. Disruptions in sectors like energy, health services, and transportation can lead to chaos, compromise safety, and weaken economic security .
Operating systems face vulnerabilities such as viruses and zero-day exploits, which can compromise system integrity. Mitigation involves patch management to address known flaws, regular application updates, and OS hardening techniques to fortify systems against potential exploits .