Cybersecurity Fundamentals
Cybersecurity protects computer systems, networks, and data from unauthorized access, damage, and disruption. It covers threat landscapes, defensive controls, risk assessment, security operations, and the principles that guide how organizations build and maintain their security posture.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — Cybersecurity Fundamentals
Cybersecurity is the work of keeping useful technology useful when it meets attack, misuse, error, or failure. This sounds less glamorous than a room full of blinking monitors, which is fortunate, because most of the job is deciding what matters before something starts blinking.
The basic puzzle has three sides. Confidentiality keeps protected information away from unauthorized readers. Integrity keeps information and system state from improper change. Availability keeps services reachable when authorized people need them. A payroll leak, an altered payment record, and an outage each ruin a different side of the puzzle. One bad event can be greedy and take all three.
The next useful shape is the risk chain. An asset is something valuable. A threat is a possible harmful event. A vulnerability is the weakness it can exploit or trigger. Impact is the harm left behind. Risk weighs possible impact and likelihood in the real setting, which is why an exposed payment service and an isolated training system do not receive the same answer merely because they share a flaw. Computers are very fond of producing identical warnings for decidedly non-identical problems.
Controls change that risk; they do not abolish it. Multifactor authentication can reduce account theft. Least privilege can limit what a stolen account can reach. Monitoring can make harmful activity visible. A response plan can guide containment. Tested recovery can restore service. These layers matter because any one of them can be misconfigured, bypassed, or unavailable at an inconvenient moment, which is the preferred moment for such things.
The NIST Cybersecurity Framework groups the operating work into Govern, Identify, Protect, Detect, Respond, and Recover. They are not six boxes to tick in a ceremonial parade. Governance sets direction. Identification supplies context. Protection and detection reduce exposure and uncertainty. Response and recovery limit harm and restore work. Lessons from recovery change the earlier choices.
Start with the Intro when the vocabulary and risk chain are still foggy. Use Slides for the relationship map, then keep the Cheatsheet nearby when assessing an asset or reviewing controls. The Practice reference turns that map into a risk record, and the exercise asks it to survive contact with a small service. The Field Notes concentrate on the awkward operational costs that appear after a control looks good on a diagram.
A scan, audit, or test is evidence for its stated scope, time, and criteria. It is not a receipt marked secure forever. Name the asset, state what must stay confidential, intact, and available, then connect threats, weaknesses, controls, and evidence. The subject is large. The first map is allowed to be smaller than the territory; it merely needs to point in the right direction.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=957258
Supports
- CSF 2.0 as an outcome-based framework for managing cybersecurity risk
- Govern, Identify, Protect, Detect, Respond, and Recover as concurrent and continuous functions
- Core, Organizational Profiles, and Tiers as framework components
- Asset, risk, safeguard, monitoring, response, recovery, and improvement outcomes used across the course
- Quiz answers about function placement, restoration, audit limits, and control selection
- https://www.nist.gov/cyberframework
Supports
- CSF 2.0 resources, quick-start guides, profiles, informative references, FAQs, and reference tooling
- The resource-center rationale in 06-links.yaml
- https://csrc.nist.gov/pubs/sp/800/12/r1/final
Supports
- High-level information security principles, requirements, risk management, and control families
- Foundational scope and layered security guidance in the introduction, slides, cheatsheet, and quiz
- The first study-path rationale in 06-links.yaml
- https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
Supports
- Security and privacy control catalog for systems and organizations
- Administrative, operational, and technical control areas
- Control families covering access, awareness, audit, configuration, contingency, identity, incident response, physical protection, risk, system integrity, and supply chain risk
- Layered control and privileged-monitoring quiz answers
- The control-catalog rationale in 06-links.yaml
- https://csrc.nist.gov/pubs/sp/800/61/r3/final
Supports
- Incident response integrated throughout CSF 2.0 cybersecurity risk management
- Preparation to reduce incident number and impact and improve detection, response, and recovery
- Response, recovery, improvement, and recurring-cause guidance across course artifacts
- Quiz answers about preparation and recurring excessive permission
- The incident-response rationale in 06-links.yaml
- https://csrc.nist.gov/glossary/term/information_security
Supports
- Information security as protection against unauthorized access, use, disclosure, disruption, modification, or destruction
- Confidentiality, integrity, and availability as foundational outcomes
- https://csrc.nist.gov/glossary/term/confidentiality
Supports
- Confidentiality definition in learner artifacts
- Confidentiality quiz answer
- https://csrc.nist.gov/glossary/term/integrity
Supports
- Integrity definition and examples in learner artifacts
- https://csrc.nist.gov/glossary/term/availability
Supports
- Availability definition and examples in learner artifacts
- Recovery quiz explanation about timely and reliable access
- https://csrc.nist.gov/glossary/term/risk
Supports
- Risk as a function of adverse impact and likelihood in context
- Risk vocabulary, prioritization guidance, and related quiz answer
- https://csrc.nist.gov/glossary/term/threat
Supports
- Threat as a circumstance or event with harmful potential
- Threat definitions across learner artifacts
- https://csrc.nist.gov/glossary/term/vulnerability
Supports
- Vulnerability as a weakness exploitable or triggerable by a threat
- Risk-chain teaching and vulnerability quiz answers
- https://csrc.nist.gov/glossary/term/security_control
Supports
- Security control as a safeguard or countermeasure protecting security outcomes
- Control vocabulary across the introduction and cheatsheet
- https://csrc.nist.gov/glossary/term/security_control_assessment
Supports
- Assessment as testing or evaluation against correct implementation, intended operation, and desired outcomes
- Bounded-evidence guidance and quiz answers about scans and audits
- https://csrc.nist.gov/glossary/term/least_privilege
Supports
- Least privilege as minimum necessary resources and authorizations
- Account, control-layering, and recurring-permission guidance and quiz answers
- https://www.cisa.gov/secure-our-world
Supports
- Recognizing and reporting phishing
- Strong passwords and password-manager use
- Multifactor authentication
- Applying software updates
- The personal-safeguards rationale in 06-links.yaml
- https://csrc.nist.gov/glossary
Supports
- NIST glossary as a collection of terms and definitions from NIST and related primary publications
- The glossary rationale in 06-links.yaml
- https://www.sei.cmu.edu/history-of-innovation/fostering-growth-in-professional-cyber-incident-management/
Supports
- The 1988 Morris Worm and the creation of the CERT Coordination Center for coordinated incident response
- The 1988 timeline milestone
- https://csrc.nist.gov/pubs/sp/800/53/final
Supports
- Original February 2005 publication of NIST SP 800-53 and its control-selection purpose
- The 2005 timeline milestone
- https://www.iso.org/cms/%20render/live/en/sites/isoorg/contents/data/standard/04/21/42103.html
Supports
- ISO/IEC 27001:2005 publication and risk-based information security management requirements
- The 2005 timeline milestone
- https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final
Supports
- NIST SP 800-34 Revision 1 contingency-planning guidance
- The 2010 timeline milestone
- https://www.nist.gov/publications/computer-security-incident-handling-guide
Supports
- NIST SP 800-61 Revision 2 and its incident handling guidance
- The 2012 timeline milestone
- https://www.nist.gov/news-events/news/2014/02/nist-releases-cybersecurity-framework-version-10
Supports
- NIST Cybersecurity Framework 1.0 release and its five functions
- The 2014 timeline milestone
- https://www.nist.gov/news-events/news/2018/04/nist-releases-version-11-its-popular-cybersecurity-framework
Supports
- NIST Cybersecurity Framework 1.1 release and its identity and supply-chain refinements
- The 2018 timeline milestone
- https://csrc.nist.gov/news/2020/sp-800-53-revision-5-published
Supports
- NIST SP 800-53 Revision 5 release, integrated security and privacy controls, and supply-chain risk management
- The 2020 timeline milestone
- https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint
Supports
- Microsoft Defender for Endpoint prevention, detection, and response capabilities
- The Microsoft Defender for Endpoint landscape entry
- https://www.crowdstrike.com/en-us/platform/endpoint-security/
Supports
- CrowdStrike Falcon endpoint detection and response capabilities
- The CrowdStrike Falcon landscape entry
- https://www.paloaltonetworks.com/cortex/cortex-xdr
Supports
- Cortex XDR correlation across endpoint, network, cloud, identity, and email data sources
- The Cortex XDR landscape entry
- https://www.splunk.com/en_us/products/enterprise-security.html
Supports
- Splunk Enterprise Security data management, analysis, and detection, investigation, and response capabilities
- The Splunk Enterprise Security landscape entry
- https://www.tenable.com/products/tenable-one
Supports
- Tenable One exposure management and attack-surface visibility
- The Tenable One landscape entry
- https://www.wiz.io/platform
Supports
- Wiz cloud security coverage for infrastructure, data, access, and workloads
- The Wiz landscape entry
- https://www.okta.com/products/workforce-identity/
Supports
- Okta Workforce Identity access, identity governance, and access-review capabilities
- The Okta Workforce Identity landscape entry
- https://www.cisa.gov/stopransomware/ransomware-guide
Supports
- Asset inventory, dependencies, criticality, and restoration priorities used in Field Notes
- The exercise guidance on asset context, least privilege, logs, recovery, and lessons learned
- https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/use-logging-on-business-systems
Supports
- Centralized log collection, protected retention, reviewed high-risk events, and response ownership used in Field Notes
- https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026
Supports
- Google Cloud observations of H2 2025 initial-access trends and the Field Notes shift card on distinct patching and identity evidence
