Skip to content

CS 331: Readings and Resources ​

Every reading in this course is free and openly licensed. There is nothing to buy.

Required text ​

The Cyber Security Body of Knowledge, version 1.1.0. Awais Rashid, Howard Chivers, Emil Lupu, Andrew Martin, and Steve Schneider (eds.), July 2021. © Crown Copyright, The National Cyber Security Centre 2021. Licensed under the Open Government Licence v3.0. http://www.nationalarchives.gov.uk/doc/open-government-licence/ Project home: https://www.cybok.org/

The complete PDF is in this course at docs/CyBOK_v1.1.0.pdf and in Canvas Files. The Open Government Licence permits redistribution with attribution, which is why the book can live inside the course instead of behind a link.

Finding a page in the PDF ​

Two page numbering systems are in play, and they do not agree:

  • Printed page numbers appear in the footer of every CyBOK page. All readings in this course are cited by printed page number.
  • Your PDF viewer's page counter is 38 higher, because the book opens with an 8-page cover block and thirty pages of front matter numbered in Roman numerals. Some viewers read the PDF's page labels and show the printed number instead.

Navigate by section number, not page number. Section numbers such as §10.4 are stable and appear in the PDF's bookmarks panel and in your viewer's search box. Page numbers are given in the schedule so you can estimate how long a reading is, not as the primary way to find it.

What we read, and what we skip ​

CyBOK has 21 knowledge areas across 22 chapters. This course is the first security course most students take and is capped at eight hours of work per week, so we use about a third of the book, deliberately. The table below is the whole book, so you can see both what is assigned and what is not.

ChKnowledge AreaPrinted p.Used in CS 331
1Introduction1Weeks 1-2: §1.1-1.5
2Risk Management and Governance19Week 4: §2.2-2.4, §2.6.1-2.6.2, §2.6.6
3Law & Regulation49Week 3: §3.1, §3.4-3.5 (skim), §3.13
4Human Factors145Week 2: §4.3-4.4
5Privacy & Online Rights171Week 3: §5.2-5.3
6Malware & Attack Technologies201Week 12: §6.1-6.2, §6.4
7Adversarial Behaviours223Week 12: §7.2
8Security Operations & Incident Management251Week 15: §8.1-8.2, §8.3.1-8.3.3, §8.3.6, §8.7
9Forensics289Not assigned
10Cryptography321Weeks 7-8: §10.3-10.8
11Operating Systems and Virtualisation357Not assigned
12Distributed Systems Security393Not assigned
13Formal Methods for Security425Not assigned
14Authentication, Authorisation & Accountability465Weeks 5-6: §14.1-14.3, §14.5, §14.6
15Software Security497Week 13: §15.1.1, §15.2, §15.4
16Web & Mobile Security523Week 14: §16.2.6-16.2.8, §16.3.1, §16.4.1
17Secure Software Lifecycle557Week 13: §17.4 only
18Applied Cryptography593Week 10: §18.3, §18.5.1
19Network Security645Week 11: §19.1, §19.3.2-19.3.3, §19.4
20Hardware Security681Not assigned
21Cyber-Physical Systems Security707Not assigned
22Physical Layer & Telecommunications Security741Not assigned

Reference sections: Bibliography p. 773 · Acronyms p. 929 · Glossary p. 951 · Index p. 963. The glossary is the source for the Key terms list on every lecture notes page: it is worth bookmarking.

Why those chapters are not assigned ​

This is a design decision, not an oversight. A future instructor should know the reasoning:

Not assignedWhy
9 ForensicsLegal-process heavy (the Daubert standard, chain of custody); belongs in a dedicated digital forensics course.
11 Operating Systems and VirtualisationAssumes an operating systems course; our prerequisite floor is one programming course.
12 Distributed Systems SecurityAssumes distributed systems background.
13 Formal Methods for SecurityRequires logic and proof techniques well past this audience.
17 Secure Software Lifecycle (except §17.4)Assumes professional software engineering experience; §17.4 is kept because it is the course's only source on organizational assurance evidence.
20 Hardware SecurityRequires digital design and computer architecture.
21 Cyber-Physical Systems SecurityDomain-specific; better as a follow-on elective.
22 Physical Layer & Telecommunications SecurityRequires signals and communications theory.
10.1 Mathematics, 10.2 Cryptographic Security ModelsThe two most mathematical sections of the cryptography chapter; the course starts at §10.3 and teaches cryptography by what it provides rather than by its proofs.

Weekly supplements ​

CyBOK is a reference, not a tutorial. One accessible supplement is paired with it in the weeks where a worked treatment helps most. All are free.

WeekSupplementLicenseLink
2Saltzer and Schroeder, The Protection of Information in Computer Systems (1975), the eight design principles in §I onlyFree to readhttps://web.mit.edu/Saltzer/www/publications/protection/
5NIST SP 800-63B-4, Digital Identity Guidelines: Authentication and Authenticator Management (July 2025), §3Public domain (U.S. Government)https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63B-4.pdf
7-8Nakov, Practical Cryptography for Developers, the AES, cipher modes, hashing, RSA, and ECC pagesMIThttps://cryptobook.nakov.com/
12MITRE ATT&CK: Enterprise matrix and selected technique pagesFree to use, MITRE termshttps://attack.mitre.org/
13Aleph One, Smashing the Stack for Fun and Profit, Phrack 49, first third onlyFree to readhttp://phrack.org/issues/49/14.html
14OWASP Top 10:2021: A01 Broken Access Control, A03 Injection, A07 Identification and Authentication FailuresCC BY-SAhttps://top10.owasp.org/2021/
15NIST SP 800-61r3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management (April 2025)Public domain (U.S. Government)https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r3.pdf

Two more references are used inside labs rather than as assigned reading:

Used inResourceLink
Lab 0CVE Program: look up one published vulnerabilityhttps://www.cve.org/
Lab 8Compiler Explorer: inspect the assembly a C function compiles to, in the browserhttps://godbolt.org/

Course data files ​

Labs use small data files that ship with the course: two written scenarios (a system description and an incident report), a vulnerable C program, five commented Python scripts, and two log files. See Course Data Files for what each one is and which lab uses it. Nothing there requires a virtual machine, a server, or an internet connection.

Software ​

ToolNeeded forNotes
Python 3.11+Labs 4, 5, 6, and 9 (optional in Lab 10) and the week 5 worked exampleFree from https://www.python.org/downloads/, and Lab 0 checks your version
cryptography packageLabs 4, 5, and 6 onlypip install cryptography; installed step by step in Lab 0
A web browserLabs 0, 6, 7, 8Any modern browser

No virtual machine, no Docker, no Linux server, no git, no GitHub account.

Links between course pages work both here and in Canvas.

Attribution and reuse ​

CyBOK material reproduced or paraphrased in course pages is used under the Open Government Licence v3.0 and is attributed as: "Adapted from The Cyber Security Body of Knowledge v1.1.0, © Crown Copyright, The National Cyber Security Centre 2021, licensed under the Open Government Licence v3.0."

Course materials in this repository are released under the MIT License, like the rest of the site repository.

Released under the MIT License.