0.03 D1: Introductions and the Security Mindset
Week 1 · 15 points · about 45 minutes · Canvas discussion board
Objectives assessed
- 1.2: Use the terms threat, vulnerability, attack, and risk correctly in writing about a security incident. (TLO 1)
Time estimate
| Initial post | 30 min |
| One reply | 15 min |
| Total | 45 min |
Why this one exists
Two reasons. The first is that this is an asynchronous course with students from several departments, and it helps everyone (me included) to know who is in the room. The second is that the four words in objective 1.2 get used interchangeably in ordinary speech and precisely in this course, and the fastest way to learn the difference is to try to use them and get corrected.
Initial Post Directions
Due: Thursday of week 1. About 250-350 words.
Post one message with two parts.
Part 1: Who you are
Two or three sentences: your major, your year, and one sentence on why you are taking this course. If you already work in IT or have any security experience, say so: it helps me calibrate. If this is completely new to you, say that too; you are the audience this course is designed for.
Part 2: Something that failed
Pick one security failure and write about it. It can be:
- Something you read about: a breach, a ransomware incident, an outage.
- Something that happened to you or someone you know: a compromised account, a phishing email that almost worked, a lost device.
- Something at a place you have worked, described in a way that does not identify the employer or anyone involved.
Do not pick the most famous breach you can think of. Pick one you can say something specific about.
Then, using the definitions from CyBOK §1.3 and the Glossary, write four short paragraphs, one each, clearly labeled:
- The vulnerability. What weakness made this possible? A weakness is a property of the system, not a person and not an event.
- The threat. Who or what had the potential to exploit it, and what did they want?
- The attack. What actually happened, the sequence of events.
- The risk. Before this happened, how likely was it and how bad would it be? Would a reasonable person have prioritized fixing it, and what else would have been competing for the same money?
If you are not sure whether something is a vulnerability or a threat, say so in your post and explain your uncertainty. That is a better post than a confident wrong answer, and it is more useful to the class.
Reply Post Directions
Due: Sunday of week 1. One reply, about 100-150 words.
Reply to one classmate whose incident is different from yours. Do one of these:
- Push on a category. If you think something they labeled a threat is really a vulnerability, say so and explain why. Be specific and be kind; everybody is doing this for the first time.
- Add the goal. Which of confidentiality, integrity, and availability did their incident break? Say which and why.
- Question the risk paragraph. Would you have prioritized fixing this beforehand? What would you have deprioritized to pay for it?
"Great post, I agree" is not a reply and earns nothing.
Rubric
| Row | What is assessed | Points |
|---|---|---|
| 1 | Initial post: introduction present; a specific incident described; all four terms (vulnerability, threat, attack, risk) used in separate labeled paragraphs and used correctly, or with the uncertainty named | 10 |
| 2 | One substantive reply to a classmate that does one of the three things above | 5 |
| Total | 15 |
Discussion Guidelines
- Do not name real individuals as the cause of an incident, including yourself. Describe roles and systems.
- Do not post anything confidential from a current or former employer. Change identifying details.
- Do not post working attacks against any system, including your own.
- Disagree with the argument, not the person.
AI disclosure
You may use AI tools. If you do, add a sentence saying which and what for, per the AI policy. Part 1 asks who you are, and Part 2 works best from something you actually know about.