CIA Triad & Target Breach Analysis
CIA Triad & Target Breach Analysis
FOR
INFORMATION ASSURANCE AND SECURITY 2
Prepared by:
Lester R. Ladera
Instructor
ACTIVITY 1:
A. Activity Title:
"The CIA Triad in Real Life: Analyzing Information Security Cases"
B. Activity Overview:
This activity introduces students to the foundational concepts of information security by
analyzing real-life cases of data breaches. Students will examine how breaches affect the
confidentiality, integrity, and availability (CIA) of data, and relate these to security concepts
such as authentication, authorization, non-repudiation, and encryption.
1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
1. Research one real-world information security breach (e.g., Yahoo 2013, Equifax
2017, or any local case).
2. Create a one-page report that includes the following:
o Brief summary of the incident (what happened, when, who was affected)
o Which parts of the CIA triad were violated and how
o Potential causes of the breach (technical or human factors)
o Recommendations on how it could have been prevented using authentication,
encryption, or access control
3. Reflect briefly on how this case shows the importance of security to society.
4. Submit your report with a clear, organized layout.
E. Expected Output:
A one-page written analysis of the security breach, correctly identifying CIA elements
Clear application of at least two information security concepts
Proper formatting, reflection, and integration of institutional values
F. Quiz
A 20 items multiple choice quiz had given after the activity.
ACTIVITY 2:
A. Activity Title:
Case Study: A ‘Kill Chain’ Analysis of the 2013 Target Data Breach
B. Activity Overview:
This activity guides students in analyzing the 2013 Target data breach using the Cyber Kill
Chain framework. Through this case study, learners will examine how the attack progressed
through different stages and identify weaknesses in Target’s security posture. The goal is to
deepen understanding of information security concepts such as confidentiality,
authentication, and breach consequences.
1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
1. Research the 2013 Target data breach and summarize key facts (timeline, attackers’
method, impact).
2. Using the Cyber Kill Chain model, analyze the attack by outlining how each of the 7
stages (Reconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command & Control, Actions on Objectives) occurred.
3. For each stage, describe how Target could have responded or prevented the attack.
4. Reflect on which parts of the CIA triad were compromised and how.
5. Present your case study in a 1–2 page report or visual slide (PowerPoint or Canva
accepted).
E. Expected Output:
The 2013 Target data breach serves as a crucial reminder of the ever-
present threats in cybersecurity. By analyzing the breach through the kill
chain framework, organizations can gain valuable insights into how
attacks unfold and develop strategies to safeguard their systems.
Strengthening security measures, particularly regarding third-party
vendors and network segmentation, is vital in preventing future cyber
incidents and protecting sensitive customer data.
Questions:
A. Activity Title:
Case Study: Analyzing the Equifax Data Breach
B. Activity Overview:
This case study aims to enhance students’ understanding of real-world data breaches through
a detailed examination of the 2017 Equifax incident. Students will assess the breach in terms
of security vulnerabilities, the CIA triad, and applicable information security concepts such as
authentication and encryption.
1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
Answer the following questions based on your research of the Equifax Data Breach (2017):
E. Expected Output:
A. Activity Title:
Case Study: Cybersecurity Breach in Law Enforcement
B. Activity Overview:
This activity explores a case involving a cybersecurity breach within a law enforcement
agency. Students will analyze the causes, impacts, and possible mitigations of the incident,
focusing on security awareness, policy enforcement, and ethical responsibility. This will help
deepen their understanding of practical information security challenges in critical sectors.
1. Practice in the classroom the VMGO and core values of the institution.
2. Identify the potential consequences of security breaches for individuals,
organizations, and society.
3. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
4. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
Read the case scenario about a Cybersecurity Breach at ISU-PD, then answer the following
questions:
E. Expected Output:
Situation:
The Ifugao State University Police Department (ISU-PD) recently implemented a new cyber
incident response system to protect sensitive case files from cyber threats. The system,
managed by the IT Department, aimed to detect and mitigate attacks such as phishing, malware,
and unauthorized access attempts. However, last week, the department fell victim to a phishing
attack that compromised critical case files, including evidence in an ongoing criminal
investigation.
A police officer, unaware of cybersecurity risks, received an email from what appeared to be the
"ISU-PD IT Support Team." The email urged the officer to reset their password via a provided
link. Without verifying its authenticity, the officer complied. Unbeknownst to them, the link
directed them to a fake website controlled by cybercriminals, who then gained access to the
police network.
The breach led to the deletion of key evidence and the leak of sensitive witness information,
causing delays in legal proceedings. The IT Department detected the intrusion after noticing
unusual activity but was unable to fully recover the lost data. As a result, an internal
investigation was launched, and new cybersecurity protocols were mandated.
Discussion Questions:
1. What mistakes led to the cybersecurity breach at ISU-PD?
The primary mistake was the officer's failure to verify the legitimacy of the email. Additionally,
the IT Department lacked strong multi-factor authentication (MFA) and cybersecurity
awareness training for officers.
3. What immediate actions should the IT Department take to mitigate the damage?
Conduct a forensic analysis, reset all credentials, strengthen firewall rules, and notify affected
individuals. Implement an incident response plan to handle future breaches effectively.
5. How can law enforcement agencies balance cybersecurity with operational efficiency?
By integrating automated cybersecurity systems that require minimal manual intervention,
conducting routine security audits, and ensuring that officers can quickly adapt to new security
measures without hindering their work.
ACTIVITY 5
A. Activity Title:
Case Analysis: Online Privacy and Protection of Children’s Information
B. Activity Overview:
This activity encourages students to explore real-world implications of laws and practices
designed to protect the privacy and security of children’s information online. Students will
analyze scenarios involving educational records, online platforms, and age-verification
challenges while applying their knowledge of legal frameworks and security principles.
1. Describe the types of information considered sensitive and protected under laws
relating to children and educational records.
2. Recognize common threats and risks faced by children online.
3. Explore the methods used to verify age and ensure privacy in online environments.
D. Activity Instructions:
Answer the following questions based on your research and understanding of information
security laws protecting children:
1. What types of personal information are protected under laws like COPPA and FERPA
in relation to children and educational records?
2. Identify three common online threats that target children today.
3. Describe one real-life case or news story involving a breach of children's data privacy.
What went wrong?
4. What age-verification methods do websites or apps commonly use, and what are their
limitations?
5. Suggest two best practices for educational institutions or platforms to better protect
children’s data online.
E. Expected Output:
A. Activity Title:
Digital Privacy Case Reflection: Living in the Surveillance Era
B. Activity Overview:
In this activity, students will critically examine how personal data is collected, shared, and
potentially misused in today's interconnected world. Emphasis is placed on understanding
threats to privacy, particularly through wireless technologies and people-based platforms like
social media. Students will reflect on real-life scenarios and propose strategies to protect their
digital footprint.
1. Identify and describe various threats to personal data privacy in the digital era, such as
cyberattacks, data breaches, and identity theft.
2. Understand how these technologies can both enhance and compromise data security.
3. Explore the impact of social media, online tracking, and data collection practices on
personal privacy.
4. Develop strategies for individuals to protect their privacy and manage their digital
footprint.
D. Activity Instructions:
Answer the following questions based on your knowledge and research:
1. Describe three common threats to personal data privacy in today’s digital world.
2. How do wireless technologies (e.g., public Wi-Fi, Bluetooth) expose users to privacy
risks?
3. What role does social media play in the erosion of personal privacy? Provide an
example.
4. Discuss a real-world data breach involving personal data. What were the
consequences?
5. Propose three actionable strategies individuals can use to protect their personal data
and limit online tracking.
E. Expected Output:
A. Activity Title:
Case Study Analysis: Data Breach at SecureMed Health Services
B. Activity Overview:
This case study examines a data breach incident at SecureMed Health Services, a fictional
healthcare provider. Students will analyze the key cybersecurity lapses that led to the breach,
evaluate how these risks could have been identified earlier, and propose strategies to prevent
similar incidents. Emphasis will be placed on organizational responsibility, legal
implications, and risk management.
D. Activity Instructions:
Answer the following five questions based on your analysis of the SecureMed case:
E. Expected Output:
A 1–2 page written report with clear, concise answers to all five questions.
Answers should demonstrate understanding of real-world cybersecurity practices and
legal implications.
Optional: Students may include a simple infographic or risk mitigation chart to
enhance their analysis.
Case Study 6: Data Breach at SecureMed Health Services
Discussion Questions:
A. Activity Title:
Case Study: Risk Assessment of a New Online Learning Platform
B. Activity Overview:
This activity explores the security considerations of implementing a new online learning
platform in a school setting. Students will analyze potential threats, identify vulnerabilities,
and evaluate appropriate risk management strategies to protect student data and maintain
system integrity.
D. Activity Instructions:
Read the case study scenario: A school recently adopted a new online learning platform to
support remote and blended learning. The platform collects student data and provides access
to course materials, communication tools, and assessment modules.
1. What are at least two threats the school might face in using the platform? Why are
these considered threats?
2. Identify one vulnerability in the case that could lead to a breach of student data. How
could it be exploited?
3. Recommend one risk mitigation strategy and explain how it would improve the
school’s security posture.
4. Do you think transferring risk (e.g., to a third-party security provider) is a good
option in this case? Why or why not?
5. If the school chooses to accept a risk, what kind of risk would be reasonable to
accept, and why?
E. Expected Output:
Prepared by:
Lester R. Ladera
Instructor
ACTIVITY 1:
A. Activity Title:
"The CIA Triad in Real Life: Analyzing Information Security Cases"
B. Activity Overview:
This activity introduces students to the foundational concepts of information security by
analyzing real-life cases of data breaches. Students will examine how breaches affect the
confidentiality, integrity, and availability (CIA) of data, and relate these to security concepts
such as authentication, authorization, non-repudiation, and encryption.
5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
5. Research one real-world information security breach (e.g., Yahoo 2013, Equifax
2017, or any local case).
6. Create a one-page report that includes the following:
o Brief summary of the incident (what happened, when, who was affected)
o Which parts of the CIA triad were violated and how
o Potential causes of the breach (technical or human factors)
o Recommendations on how it could have been prevented using authentication,
encryption, or access control
7. Reflect briefly on how this case shows the importance of security to society.
8. Submit your report with a clear, organized layout.
E. Expected Output:
A one-page written analysis of the security breach, correctly identifying CIA elements
Clear application of at least two information security concepts
Proper formatting, reflection, and integration of institutional values
F. Quiz
A 20 items multiple choice quiz had given after the activity.
ACTIVITY 2:
A. Activity Title:
Case Study: A ‘Kill Chain’ Analysis of the 2013 Target Data Breach
B. Activity Overview:
This activity guides students in analyzing the 2013 Target data breach using the Cyber Kill
Chain framework. Through this case study, learners will examine how the attack progressed
through different stages and identify weaknesses in Target’s security posture. The goal is to
deepen understanding of information security concepts such as confidentiality,
authentication, and breach consequences.
5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
6. Research the 2013 Target data breach and summarize key facts (timeline, attackers’
method, impact).
7. Using the Cyber Kill Chain model, analyze the attack by outlining how each of the 7
stages (Reconnaissance, Weaponization, Delivery, Exploitation, Installation,
Command & Control, Actions on Objectives) occurred.
8. For each stage, describe how Target could have responded or prevented the attack.
9. Reflect on which parts of the CIA triad were compromised and how.
10. Present your case study in a 1–2 page report or visual slide (PowerPoint or Canva
accepted).
E. Expected Output:
The 2013 Target data breach was one of the most significant cybersecurity
incidents in history, compromising the personal and financial data of over
70 million customers. This breach was made possible due to
vulnerabilities in Target’s third-party vendor, Fazio Mechanical Services, an
HVAC company with remote access to Target’s network for billing
purposes. Attackers exploited these weaknesses to infiltrate Target’s
systems, install malware, and extract sensitive customer information. The
breach serves as a critical lesson on the importance of robust
cybersecurity measures, particularly concerning third-party vendors and
network segmentation.
The impact of the breach was severe. Financially, Target incurred over
$200 million in legal fees, settlements, and fines. The company also
suffered reputational damage, as customers lost trust in its ability to
protect their personal information. Additionally, the breach attracted
heightened regulatory scrutiny, leading to increased focus on supply chain
security and vendor risk management.
The 2013 Target data breach serves as a crucial reminder of the ever-
present threats in cybersecurity. By analyzing the breach through the kill
chain framework, organizations can gain valuable insights into how
attacks unfold and develop strategies to safeguard their systems.
Strengthening security measures, particularly regarding third-party
vendors and network segmentation, is vital in preventing future cyber
incidents and protecting sensitive customer data.
Questions:
Rubrics
ACTIVITY 3:
A. Activity Title:
Case Study: Analyzing the Equifax Data Breach
B. Activity Overview:
This case study aims to enhance students’ understanding of real-world data breaches through
a detailed examination of the 2017 Equifax incident. Students will assess the breach in terms
of security vulnerabilities, the CIA triad, and applicable information security concepts such as
authentication and encryption.
5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
Answer the following questions based on your research of the Equifax Data Breach (2017):
E. Expected Output:
ACTIVITY 4
A. Activity Title:
Case Study: Cybersecurity Breach in Law Enforcement
B. Activity Overview:
This activity explores a case involving a cybersecurity breach within a law enforcement
agency. Students will analyze the causes, impacts, and possible mitigations of the incident,
focusing on security awareness, policy enforcement, and ethical responsibility. This will help
deepen their understanding of practical information security challenges in critical sectors.
5. Practice in the classroom the VMGO and core values of the institution.
6. Identify the potential consequences of security breaches for individuals,
organizations, and society.
7. Illustrate how each component of the CIA triad is essential for ensuring the security
and reliability of information systems.
8. Describe fundamental information security concepts such as authentication,
authorization, non-repudiation, and encryption.
D. Activity Instructions:
Read the case scenario about a Cybersecurity Breach at ISU-PD, then answer the following
questions:
E. Expected Output:
Situation:
The Ifugao State University Police Department (ISU-PD) recently implemented a new cyber
incident response system to protect sensitive case files from cyber threats. The system,
managed by the IT Department, aimed to detect and mitigate attacks such as phishing, malware,
and unauthorized access attempts. However, last week, the department fell victim to a phishing
attack that compromised critical case files, including evidence in an ongoing criminal
investigation.
A police officer, unaware of cybersecurity risks, received an email from what appeared to be the
"ISU-PD IT Support Team." The email urged the officer to reset their password via a provided
link. Without verifying its authenticity, the officer complied. Unbeknownst to them, the link
directed them to a fake website controlled by cybercriminals, who then gained access to the
police network.
The breach led to the deletion of key evidence and the leak of sensitive witness information,
causing delays in legal proceedings. The IT Department detected the intrusion after noticing
unusual activity but was unable to fully recover the lost data. As a result, an internal
investigation was launched, and new cybersecurity protocols were mandated.
Discussion Questions:
1. What mistakes led to the cybersecurity breach at ISU-PD?
The primary mistake was the officer's failure to verify the legitimacy of the email. Additionally,
the IT Department lacked strong multi-factor authentication (MFA) and cybersecurity
awareness training for officers.
3. What immediate actions should the IT Department take to mitigate the damage?
Conduct a forensic analysis, reset all credentials, strengthen firewall rules, and notify affected
individuals. Implement an incident response plan to handle future breaches effectively.
ACTIVITY 5
A. Activity Title:
Case Analysis: Online Privacy and Protection of Children’s Information
B. Activity Overview:
This activity encourages students to explore real-world implications of laws and practices
designed to protect the privacy and security of children’s information online. Students will
analyze scenarios involving educational records, online platforms, and age-verification
challenges while applying their knowledge of legal frameworks and security principles.
4. Describe the types of information considered sensitive and protected under laws
relating to children and educational records.
5. Recognize common threats and risks faced by children online.
6. Explore the methods used to verify age and ensure privacy in online environments.
D. Activity Instructions:
Answer the following questions based on your research and understanding of information
security laws protecting children:
6. What types of personal information are protected under laws like COPPA and FERPA
in relation to children and educational records?
7. Identify three common online threats that target children today.
8. Describe one real-life case or news story involving a breach of children's data privacy.
What went wrong?
9. What age-verification methods do websites or apps commonly use, and what are their
limitations?
10. Suggest two best practices for educational institutions or platforms to better protect
children’s data online.
E. Expected Output:
A. Activity Title:
Digital Privacy Case Reflection: Living in the Surveillance Era
B. Activity Overview:
In this activity, students will critically examine how personal data is collected, shared, and
potentially misused in today's interconnected world. Emphasis is placed on understanding
threats to privacy, particularly through wireless technologies and people-based platforms like
social media. Students will reflect on real-life scenarios and propose strategies to protect their
digital footprint.
5. Identify and describe various threats to personal data privacy in the digital era, such as
cyberattacks, data breaches, and identity theft.
6. Understand how these technologies can both enhance and compromise data security.
7. Explore the impact of social media, online tracking, and data collection practices on
personal privacy.
8. Develop strategies for individuals to protect their privacy and manage their digital
footprint.
D. Activity Instructions:
Answer the following questions based on your knowledge and research:
6. Describe three common threats to personal data privacy in today’s digital world.
7. How do wireless technologies (e.g., public Wi-Fi, Bluetooth) expose users to privacy
risks?
8. What role does social media play in the erosion of personal privacy? Provide an
example.
9. Discuss a real-world data breach involving personal data. What were the
consequences?
10. Propose three actionable strategies individuals can use to protect their personal data
and limit online tracking.
E. Expected Output:
A. Activity Title:
Case Study Analysis: Data Breach at SecureMed Health Services
B. Activity Overview:
This case study examines a data breach incident at SecureMed Health Services, a fictional
healthcare provider. Students will analyze the key cybersecurity lapses that led to the breach,
evaluate how these risks could have been identified earlier, and propose strategies to prevent
similar incidents. Emphasis will be placed on organizational responsibility, legal
implications, and risk management.
D. Activity Instructions:
Answer the following five questions based on your analysis of the SecureMed case:
E. Expected Output:
A 1–2 page written report with clear, concise answers to all five questions.
Answers should demonstrate understanding of real-world cybersecurity practices and
legal implications.
Optional: Students may include a simple infographic or risk mitigation chart to
enhance their analysis.
Case Study 6: Data Breach at SecureMed Health Services
Discussion Questions:
6. What were the key risks that led to the breach?
A. Activity Title:
Case Study: Risk Assessment of a New Online Learning Platform
B. Activity Overview:
This activity explores the security considerations of implementing a new online learning
platform in a school setting. Students will analyze potential threats, identify vulnerabilities,
and evaluate appropriate risk management strategies to protect student data and maintain
system integrity.
D. Activity Instructions:
Read the case study scenario: A school recently adopted a new online learning platform to
support remote and blended learning. The platform collects student data and provides access
to course materials, communication tools, and assessment modules.
6. What are at least two threats the school might face in using the platform? Why are
these considered threats?
7. Identify one vulnerability in the case that could lead to a breach of student data. How
could it be exploited?
8. Recommend one risk mitigation strategy and explain how it would improve the
school’s security posture.
9. Do you think transferring risk (e.g., to a third-party security provider) is a good
option in this case? Why or why not?
10. If the school chooses to accept a risk, what kind of risk would be reasonable to
accept, and why?
E. Expected Output:
Scenario:
Saint Gabriel High School has recently adopted a new online learning
platform to enhance digital learning and facilitate hybrid education. This
new system allows students and teachers to access lessons, assignments,
grades, and communication tools online. While the new platform promises
better learning outcomes and improved access to educational resources,
its implementation introduces potential security risks.
The IT department realized that the platform had not been updated
with the latest security patches.
Task:
Assessment Questions:
1. What are at least two threats that the school might face in using the
new online learning platform? Explain why they are threats.