Cybersecurity Fundamentals
Foundations every security practitioner shares — threat landscape, CIA + AAA, risk management, defense in depth, MITRE ATT&CK, networking and OS essentials for security, cryptographic primitives, and the NIST Cybersecurity Framework. Eight AI-led lessons plus three hands-on labs.
View badge details
About This Course
Build the foundation that every security practitioner shares. Over eight AI-led teaching lessons and three hands-on labs, you will learn the vocabulary and mental models the rest of the Cybersecurity Professional skill path depends on: the modern threat landscape and the actors who populate it, the CIA triad and AAA model, risk-management thinking, defense in depth with the MITRE ATT&CK framework, essential networking and operating-system knowledge for security work, cryptographic primitives, and the NIST Cybersecurity Framework. By the end of this course you will be able to describe the modern threat landscape, reason about risk in business terms, read a security control taxonomy, navigate the MITRE ATT&CK Navigator, use OpenSSL to inspect cryptographic artifacts, and self-assess an organization against the NIST Cybersecurity Framework.
Course Curriculum
11 Lessons
The threat landscape today
Learn to describe the modern cybersecurity threat landscape and the four actor categories that populate it. By the end of this lesson you will be able to name nation-state, criminal, insider, and hacktivist actors, identify each one's primary motivation and operational signature, classify a described incident vignette as the work of a specific actor category, and compare today's landscape to the 2015 baseline on the dimensions that shape every control decision that follows.
The CIA triad and AAA
Learn the two foundational models every security practitioner shares — the CIA triad (Confidentiality, Integrity, Availability) and the AAA model (Authentication, Authorization, Accounting + non-repudiation as the practical fourth). By the end of this lesson you will be able to define each property, classify a given incident along both axes, and explain why maximizing all three CIA properties simultaneously is always a tradeoff rather than a technical gap.
Risk management
Learn how security practitioners reason about risk and keep it visible to the business. By the end of this lesson you will be able to explain the threat × vulnerability × impact model, compare qualitative and quantitative risk analysis, classify a given risk treatment choice as Mitigate, Transfer, Avoid, or Accept, and name the mandatory fields of a usable risk-register entry.
Defense in depth and the MITRE ATT&CK primer
Learn the layered-controls model that modern security programs are built around and the industry-standard framework for talking about adversary behavior. By the end of this lesson you will be able to describe defense in depth across people, process, and technology layers, walk the Lockheed Martin kill chain stage by stage, map an attacker action to the MITRE ATT&CK tactic and technique it exercises, and explain why detection at an earlier kill-chain stage beats detection at a later one.
Explore the MITRE ATT&CK Navigator - Lab Exercises
Walk through the MITRE ATT&CK Navigator — the industry-standard web tool for exploring adversary tactics, techniques, and procedures. You will build a Beacon Harbor Financial baseline coverage layer, overlay a specific threat group's techniques, and produce the detection-engineering backlog that drives the SOC team's next quarter of work. By the end of this lab you will be able to use ATT&CK Navigator to communicate detection coverage to a technical peer and build a prioritized SOC backlog of your own.
Networking essentials for security
Learn the networking primitives security work depends on. By the end of this lesson you will be able to identify the OSI layer at which a given security control operates, explain the TCP three-way handshake and distinguish TCP from UDP, describe why DNS logs are a disproportionately valuable detection surface, and compare a flat network to a segmented one with Zero Trust as the modern architectural response.
Operating system essentials for security
Learn the operating-system internals that security work depends on, in both the Windows and Linux worlds. By the end of this lesson you will be able to identify the five OS primitives every practitioner reads, match a described attacker behavior to the specific Windows Event ID or Linux auditd rule key that would surface it, and compare equivalent event sources between Windows and Linux.
Cryptography essentials
Learn the cryptographic primitives security practitioners rely on every day. By the end of this lesson you will be able to distinguish symmetric from asymmetric encryption and name correct use cases for each, explain what cryptographic hashing does and does not guarantee, describe a digital-signature workflow end-to-end, and walk through the TLS handshake stage by stage. The hands-on OpenSSL lab that follows this lesson gives you commands that produce every one of these artifacts.
Hands-on cryptography with OpenSSL - Lab Exercises
Note: This lab pre-provisions an Azure Linux VM at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Translate the cryptography concepts from Lesson 7 into working artifacts you can produce and inspect on your own. You will use the OpenSSL command-line tool on an Ubuntu VM to generate an RSA key pair, encrypt and decrypt a file symmetrically and asymmetrically, sign and verify a message, and inspect a live TLS handshake against a public host. By the end of this lab you will be able to use OpenSSL to produce and read every cryptographic artifact introduced in the lesson.
Security control taxonomy
Learn the taxonomy security practitioners use to classify every control they design, inherit, or audit — administrative, technical, and physical, each operating in a preventive, detective, or corrective role. By the end of this lesson you will be able to classify a given Beacon Harbor control along both axes, name the taxonomy's blind spots, and describe how the taxonomy maps to the audit frameworks (SOC 2, ISO 27001, NIST CSF) that structure Beacon Harbor's compliance program.
NIST CSF self-assessment of Beacon Harbor Financial - Lab Exercises
Walk through a full NIST Cybersecurity Framework (CSF 2.0) self-assessment of Beacon Harbor Financial. You will score Beacon Harbor against each of the six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover), identify the two weakest subcategories, and draft the one-page summary a CISO would hand to the board. By the end of this lab you will be able to run a CSF self-assessment of a real organization and communicate the results to a non-technical audience — the deliverable every mature security program produces annually.