High School BeginnerModule B15Lesson 1 of 7

B15.1 Cybersecurity Foundations Review

Review confidentiality, integrity, availability, assets, threats, vulnerabilities, risk, controls, defense in depth, evidence, and the defender mindset.

Lesson Progress

Cybersecurity Foundations Review

High School BeginnerB15: Beginner Capstone Review • Lesson 1 of 7

14% complete

Readiness Check

Before You Start

0/3 ready

Capstone Hook

Every Cybersecurity Decision Begins With What Matters and What Could Harm It

Cybersecurity is not only about tools. Defenders identify valuable assets, understand threats and vulnerabilities, estimate possible impact, choose controls, review evidence, and improve protection over time.

Review rule: strong conclusions come from evidence and context. An alert, weakness, or unusual event is not automatically a confirmed incident.

Learning Objective

Explain the CIA triad and connect each principle to real defensive goals.

Learning Objective

Distinguish assets, threats, vulnerabilities, risks, impacts, and controls.

Learning Objective

Build a layered protection plan using evidence, priorities, and defense in depth.

Why This Matters

Foundations Help Defenders Explain Why a Control Is Needed

A password manager, update, backup, access review, firewall rule, or training program is more meaningful when the defender can explain which asset it protects, which risk it reduces, and what evidence shows it is working.

Visual Review

Confidentiality, Integrity, and Availability

The CIA triad helps defenders ask three different protection questions about the same asset.

1

Confidentiality

Who should be allowed to view or use the information?

Access control, encryption, privacy settings, classification, secure sharing, and least privilege.

2

Integrity

How do we know the information or system has not been changed improperly?

Permissions, hashes, logs, approvals, version history, backups, and change controls.

3

Availability

Can approved users access the service or data when needed?

Updates, backups, redundancy, monitoring, incident response, and recovery planning.

Core Concept

Risk Connects Assets, Threats, Vulnerabilities, Impact, and Controls

A threat may take advantage of a vulnerability and affect an asset. Defenders estimate likelihood and impact, review existing controls, decide what additional protection is needed, and document remaining risk.

Key Vocabulary

Foundations Review Terms

Asset

Something valuable that should be protected, such as data, accounts, devices, services, reputation, or people.

Threat

A person, event, action, or condition that could cause harm to an asset.

Vulnerability

A weakness that could be used or triggered by a threat.

Risk

The possibility that a threat will use a vulnerability and cause harm to an asset.

Control

A safeguard used to prevent, detect, respond to, or recover from risk.

Defense in depth

Using multiple protective layers so one failed control does not expose everything.

Fake Risk Register

Asset → Threat → Vulnerability → Control

Each row connects something valuable with a possible source of harm, an exploitable weakness, and layered safeguards.

Fake Data

Asset

Student learning portal

Threat

Account takeover

Vulnerability

Weak reused passphrase and no MFA

Controls

Unique passphrase, password manager, MFA, login alerts, and recovery review

Asset

Teacher shared drive

Threat

Accidental exposure

Vulnerability

Public sharing link with broad permissions

Controls

Restricted sharing, access review, classification, and expiration settings

Asset

School laptop

Threat

Malicious software

Vulnerability

Unpatched software and unsafe download behavior

Controls

Updates, endpoint protection, safe browsing, reporting, and least privilege

Asset

Course database

Threat

Data loss

Vulnerability

Backups exist but restores are untested

Controls

Protected copies, restore validation, ownership, and documented recovery goals

Fake Dashboard

Fake Cybersecurity Foundations Dashboard

Training dashboard using fictional assets, risks, controls, owners, findings, and review decisions.

Assets reviewed

32

Fictional accounts, devices, applications, services, data sets, and recovery systems.

Risks requiring action

9

Weak authentication, broad sharing, missing updates, untested recovery, and unclear ownership.

Layered controls

21

Preventive, detective, response, recovery, technical, administrative, and physical safeguards.

Fake SOC Alert

Critical Learning Portal Depends on One Unverified Control

Source: Fake Risk Review Monitor • Time: 10:42 AM

High Severity
A fictional learning portal stores important course data and relies on nightly backups, but the restore process has not been tested and no recovery owner is assigned.
Defensive recommendation: Assign ownership, validate recovery through an approved test, document recovery goals, and add layered safeguards rather than relying on backup job status alone.

Fake Log Panel

Fake Foundations Review Log

training-log-viewer.log
09:18:02 ASSET name='learning_portal' criticality='high'
09:21:44 THREAT type='data_loss_or_service_failure'
09:25:16 VULNERABILITY restore_test='missing' owner='unassigned'
09:29:53 IMPACT confidentiality='medium' integrity='high' availability='high'
09:34:28 CONTROL backup_job='nightly_success'
09:39:11 GAP recovery_validation='overdue' defense_layers='insufficient'
10:42:07 DECISION assign_owner='true' validate_restore='urgent'

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Which Risk Should Be Addressed First?

A fictional course database is required for daily instruction.
Nightly backups report success, but no restore test has occurred in nine months.
The recovery owner field is empty.
A separate public information page has a minor formatting error.

What is the strongest priority decision?

Common Mistakes

Mistakes That Weaken Foundational Reasoning

Calling every unusual event a confirmed attack without reviewing evidence.
Confusing a threat with a vulnerability.
Selecting controls without identifying the asset and risk first.
Protecting confidentiality while ignoring integrity or availability.
Depending on one control instead of using layered defenses.
Writing conclusions that are stronger than the available evidence supports.

Safe Capstone Lab

Build a Fictional Risk and Control Map

Fake Organization

Community Learning Portal

The fictional organization uses student accounts, teacher accounts, managed laptops, a learning website, shared cloud storage, email, network services, and backup systems.

Review Steps

  • List the most valuable assets and their owners.
  • Identify threats and vulnerabilities separately.
  • Describe confidentiality, integrity, and availability impact.
  • Review existing preventive, detective, response, and recovery controls.
  • Identify control gaps and remaining risk.
  • Prioritize actions and document the evidence.

Scenario Decision Lab

A Shared Folder Is Publicly Accessible

A fictional teacher folder containing class resources is available through a public link, even though only enrolled students need access.

Scenario Decision Lab

One Security Tool Blocks a Suspicious File

A fictional endpoint tool blocks a suspicious file, but related email and network events remain unexplained.

Defender Habits

Cybersecurity Foundations Review Checklist

Check Your Understanding

B15.1 Mini Quiz: Cybersecurity Foundations Review

Choose your answers first. Explanations appear only after submission.

1. What is an asset in cybersecurity?

2. What is the difference between a threat and a vulnerability?

3. Which principle focuses on preventing improper changes?

4. What does defense in depth mean?

5. What is the strongest risk decision?

Portfolio Prompt

Portfolio Prompt

Create a one-page fictional cybersecurity risk and control map. Include the asset, owner, confidentiality need, integrity need, availability need, threat, vulnerability, possible impact, existing controls, control gaps, priority, remaining risk, and next action.

Use fictional organizations, systems, accounts, data, risks, and evidence only.
Show the difference between a threat and a vulnerability.
Explain why each control protects confidentiality, integrity, availability, or more than one principle.

Key Takeaways

What You Should Remember

1.Assets are protected from threats that may use vulnerabilities and cause harm.
2.Confidentiality, integrity, and availability describe different protection goals.
3.Risk decisions connect likelihood, impact, evidence, controls, priorities, and remaining risk.
4.Defense in depth uses multiple layers instead of depending on one safeguard.
5.Strong defenders explain what is known, what is uncertain, who owns the action, and what happens next.

Navigation

Continue Module B15