Skip to content

Module 3 Overview ​

January 25-31 · Reading: 15 pages, plus 14 to skim · Estimated total: 6 hours

Everything you learn in this course is dual-use. The technique that finds a vulnerability in a system you are paid to test is the same technique that is a crime against a system you are not. The line between the two is not technical, and it is not obvious. This week is about where it sits.

Three warnings before you start.

First, I am not a lawyer and this is not legal advice. CyBOK's Law & Regulation chapter is written by one, and it is careful to say the same thing. What you are learning is which kinds of question arise and who they run to, not the law of any particular jurisdiction.

Second, good intentions are not a defense. "I was going to report it" does not convert unauthorized access into authorized access. This surprises people every year.

Third, this week's reading comes from the longest chapter in the book: CyBOK's law chapter runs about 80 pages. You are assigned 15, plus 14 to skim for D2. Do not read the rest unless you want to.

Learning Objectives ​

By the end of this week, the successful student will be able to:

  • 1.5: Describe the legal, regulatory, and ethical constraints on security work, including vulnerability disclosure and privacy obligations.

Assignments and Tasks ​

Due by Thursday at 11:59 p.m. Mountain Time ​

Due by Sunday at 11:59 p.m. Mountain Time ​

Time Estimate ​

ActivityTime
Reading (15 pages, plus 14 to skim)2 hrs 25 min
The notes page and the worked example30 min
D2 post and two replies1 hr
Review and slack1 hr 50 min
Total~6 hrs

Released under the MIT License.