3.31M
AI
Категория: ИнтернетИнтернет

INTRODUCTION-TO-CYBER-SECURITY (1)

1.

DAY 1
INTRODUCTION TO
CYBER SECURITY
Beginner Cyber Security Training
Duration: 1 Hour

2.

LEARNING OBJECTIVES
By the end of this class, students should be able to:
Define Cyber Security
Understand why Cyber Security is important
Identify what Cyber Security protects
Understand the CIA Triad
Understand basic security terms
Identify common cyber threats
Understand basic Cyber Security career paths
Differentiate between attacker and defender

3.

WHAT IS CYBER SECURITY?
Definition:
Cyber Security is the practice of protecting computers, networks,
applications, devices, systems, and data from unauthorized access,
attacks, damage, theft, or disruption.
In simple words:
"Cyber Security
means protecting
digital systems and
information from
cyber threats."

4.

WHY IS CYBER SECURITY IMPORTANT?
Today, almost everything is connected to digital systems.
Banking
Hospitals
Colleges
Airports
Government systems
E-commerce
Social media
Cloud services
Mobile applications
IoT devices
If these systems are not properly protected, attackers may exploit security weaknesses.
Important point:
Data is one of the most valuable assets in a digital environment.
Banking
Financial systems and
customer data
Hospitals
Patient records and critical
systems
Interconnected
Digital Systems
Ubiquitous systems that
are widely vulnerable
E-commerce
Online stores and payment
platforms
IoT Devices
Connected sensors and smart
gadgets

5.

REAL-WORLD EXAMPLE: GMAIL ACCOUNT
Imagine that you have a Gmail account.
Your account contains:
Emails
Photos
Personal information
Contacts
Documents
If someone gets unauthorized access to your account, your information may be exposed or misused.
Cyber Security helps protect that account using:
Strong passwords
Multi-factor authentication
Access controls
Security monitoring
Encryption
Flow: User → Gmail Account → Authentication → Security Controls → Protected Account
User Access
Gmail Account
Authentication
Security Controls

6.

WHAT DOES CYBER SECURITY PROTECT?
Cyber Security protects several categories:
A. Devices
B. Networks
Laptop
Desktop
Smartphone
Server
IoT device
Wi-Fi network
LAN
Enterprise network
Internet-connected infrastructure
C. Applications
D. Data
Websites
Mobile applications
Desktop applications
APIs
Passwords
Customer information
Financial information
Student records
Company documents

7.

CIA TRIAD
The CIA Triad is one of the fundamental concepts in Cyber Security.
CIA stands for:
C → Confidentiality
I → Integrity
A → Availability

8.

CONFIDENTIALITY
Confidentiality means ensuring that information is accessible only to authorized people or systems.
Simple question:
"Who is allowed to see this information?"
Example:
Suppose a college stores student marks. Only authorized teachers and administrators should be able to access them.
Student Marks
Records of student grades.
Access Control
Verify user credentials and permissions.
Authorized User
Access granted to permitted staff.
Unauthorized User
Access denied; confidentiality preserved.
Common security controls:
Passwords

9.

INTEGRITY
Integrity means ensuring that data remains accurate, complete, and protected from unauthorized modification.
Simple question:
"Has the information been changed without
authorization?"
Example:
A student has a mark of: 85
If an unauthorized person changes it to: 95
The integrity of the data has been compromised.
Original Mark: 85
Unauthorized Change
Modified Mark: 95
Integrity Compromised

10.

AVAILABILITY
Availability means ensuring that systems and information are accessible to authorized users when needed.
Simple question:
"Can I access the system when I need it?"
Example:
Imagine an online banking application is unavailable when customers need to access their accounts.
The system has an availability problem.
Banking System
Online financial platform
System Status
Available or Unavailable
Customer Access
Access Granted
Customer Access
Access Denied

11.

IMPORTANT CYBER SECURITY TERMS
1. Asset
2. Threat
3. Vulnerability
4. Attack
5. Risk
6. Attacker
7. Malware
8. Authentication
9. Authorization
10. Encryption

12.

COMMON CYBER THREATS
Malware
Phishing
Social Engineering
Password Attacks
Data Breach
DoS/DDoS
Detailed attack concepts will be taught later.

13.

MALWARE
Malware = Malicious Software
Software designed to perform harmful or unauthorized actions.
Examples:
Virus
Worm
Ransomware
Spyware
These will be taught in detail in later classes.
Trojan

14.

PHISHING
Phishing is a social-engineering technique in which attackers use deceptive messages or websites to trick people.
Example:
A person receives:
"Your account requires immediate verification."
The message contains a suspicious link.
The user clicks it and may be directed to a fraudulent website.
Warning signs:
Unexpected message
Urgent language
Suspicious links
Unexpected attachments
Requests for sensitive information
Create a visual showing the phishing attack flow.
Deceptive
Message
Suspicious
Link
User Clicks
Fraudulent
Site

15.

SOCIAL ENGINEERING
Social engineering means manipulating or deceiving people to influence them into revealing information or performing an unsafe
action.
Example:
An attacker pretends to be a company's IT employee and asks an employee for information.
The weakness here is not necessarily the computer.
It is the human factor.
Attacker
Impersonates IT Support
Employee
Receives deceptive request
Manipulation
Trust is exploited
Action
Reveals info or performs unsafe act

16.

PASSWORD ATTACKS
Attackers may attempt to obtain or compromise passwords through different techniques.
Examples:
Brute-force attacks
Dictionary attacks
Credential stuffing
Password spraying
These will be taught in detail later.

17.

DATA BREACH
A data breach occurs when protected or sensitive information is accessed, disclosed, or exposed without
authorization.
Flow:
Company Database → Unauthorized Access → Customer Information Exposed → Data Breach
Company Database
Sensitive data stored.
Unauthorized Access
Intrusion by attacker.
Customer Information Exposed
Data compromised.
Data Breach
Resulting security incident.

18.

ATTACKER VS DEFENDER
ATTACKER:
DEFENDER:
Find weaknesses
Gain unauthorized access
Steal information
Disrupt services
Identify weaknesses
Protect systems
Monitor activity
Detect threats
Respond to incidents
Recover systems
Important:
Security testing should only be performed on systems where the tester has explicit authorization and an appropriate scope.

19.

CYBER SECURITY CAREER PATHS
SOC Analyst
Security Analyst
Monitors security alerts and investigates suspicious activity.
Analyzes security events and helps protect systems.
Penetration Tester
Security Engineer
Performs authorized security testing to identify
vulnerabilities.
Designs and implements security controls.
Incident Responder
Digital Forensics Analyst
Investigates and responds to security incidents.
Analyzes digital evidence.
Cloud Security Engineer
Application Security
Works on protecting cloud infrastructure and services.
Focuses on securing software, websites, and applications.

20.

DAY 1 HOMEWORK
Assignment:
"Cybersecurity Around Me"
Students must identify 5 digital assets they use.
For each asset:
1. Asset:
2. Threat:
3. Vulnerability:
4. Possible Impact:
5. Protection:
Example:
Asset:
Threat:
Vulnerability:
Possible Impact:
Email Account
Phishing
Weak password / No MFA
Unauthorized account access
Protection:
Strong password + MFA

21.

DAY 1 RECAP
Today we learned:
What is Cyber Security?
Why Cyber Security is important
What Cyber Security protects
CIA Triad
Asset
Threat
Vulnerability
Attack
Risk
Authentication
Authorization
Encryption
Common Cyber Threats
Attacker vs Defender
Cyber Security Career Paths

22.

TOMORROW
DAY 2
COMPUTER FUNDAMENTALS
Before learning how systems can be attacked, we need to understand the computer itself.
Tomorrow we will learn:
CPU
RAM
Storage
Operating System
Files
Processes
Users
Closing statement:
"Today we learned what we are trying to protect. Tomorrow, before we study how systems can be attacked,
we need to understand the computer itself."
English     Русский Правила