1.01 Readings and Lecture Notes
January 11-17 · Reading: 7 pages · About 1 hr 15 min with the worked example
What to do this week, and when it is due, is on the Module 1 Overview.
Readings
| Source | Sections | Printed pages | Length | Time |
|---|---|---|---|---|
| CyBOK v1.1.0 | §1.1 Cyber Security Definition | 2-4 | 3 pp | 15 min |
| CyBOK v1.1.0 | §1.2 CyBOK Knowledge Areas | 4-6 | 2 pp | 10 min |
| CyBOK v1.1.0 | §1.3 Deploying CyBOK knowledge: especially §1.3.1-1.3.3 | 6-8 | 2 pp | 20 min |
Navigating the PDF: go by section number, not page number. The printed page numbers in the footer may not match your PDF viewer's counter, because the book has 38 pages of front matter. Use your viewer's search box or the bookmarks panel. See Readings and Resources for more.
§1.2 is a map of the whole book. Skim it. You will not read most of what it lists, and Readings and Resources tells you exactly which parts of it this course uses.
Worked example
Here is one incident broken down using the four terms from §1.3: vulnerability, threat, attack, and risk. This is the form D1 asks you to produce, one labeled paragraph per term. The short definitions are under Key terms at the end of this page.
The incident. In 2023 a file transfer product used by thousands of organizations was found to contain a SQL injection flaw. Attackers exploited it to steal data from more than two thousand organizations before most of them knew the product had a problem.
The vulnerability. A SQL injection flaw in the product's web interface: user-supplied input was built into a database query as text, so input could become command. This is a property of the software. It existed whether or not anybody ever found it, and it existed before anyone attacked it.
The threat. A financially motivated criminal group with the capability to find and exploit software flaws at scale, and a business model (extortion) that rewards stealing data from many organizations at once. The threat is the potential cause of harm: the group, its capability, and its motive.
The attack. The group scanned the internet for exposed instances of the product, exploited the flaw against the ones it found, installed a web shell to keep access, and copied out the data those instances held. This is what actually happened: a sequence of events in time.
The risk. Before this happened, what would a reasonable person have said? The product handled bulk file transfers, so the impact of compromise was obviously high: that part was knowable in advance. Likelihood is harder: internet-facing software from a vendor with a history of similar flaws is a well-known risk category. So: high impact, moderate-to-high likelihood. A risk assessment that reached that conclusion would have said do not expose this to the internet, and some organizations had.
Notice four things about that example:
- The vulnerability is a property of a system. It is never a person and never an event.
- The threat exists even when nothing has happened yet.
- The attack is a sequence, described in order.
- The risk is a judgment made beforehand, combining how likely with how bad, and it competes with every other risk for the same budget.
And the three goals
Which of confidentiality, integrity, and availability did that incident break?
Confidentiality, clearly: data went to people not entitled to it. Integrity? Of the stolen files, no: the reporting does not say the attackers altered them, so resist the urge to add it. Of the server, yes: installing a web shell is an unauthorized change to the system. Availability? The files were copied, not deleted, and the victims still had them. So: confidentiality, plus the integrity of the server but not of the data.
Being able to say "no, that one was not violated, and here is why" is as much of the skill as naming the one that was.
Key terms
Adapted from the CyBOK Glossary (printed page 951) and §1.3:
| Term | Short form |
|---|---|
| Confidentiality | Information is not disclosed to those not entitled to it. |
| Integrity | Information is not altered except by those entitled to alter it, and alteration is detectable. |
| Availability | Information and services are reachable by those entitled to them, when they need them. |
| Vulnerability | A weakness in a system that could be exploited. A property of the system. |
| Threat | A potential cause of an unwanted incident. |
| Attack | A threat carried out: an actual sequence of events. |
| Risk | The combination of how likely an unwanted incident is with how much harm it would do. |
| Asset | Something of value that is worth protecting. |
Looking ahead
Week 2 takes the eight design principles that security has been using since 1975 and asks you to apply them to something you use every day. Read §1.4 before Monday if you want a head start.