At the end of this chapter, students should be able to:
The word cyber refers to computers, digital devices, communication networks and the virtual environment created through the use of these technologies. The word security means protection from danger, damage, loss or unauthorised interference.
Cybersecurity is the protection of computers, mobile devices, networks, software, digital services and information from unauthorised access, attack, damage, disruption, theft or misuse.
Cybersecurity involves the people, technologies, policies, procedures and practices used to protect digital systems and information.
Cyberspace is the digital environment created by computers, mobile devices, networks, software applications, websites, cloud systems and internet-connected services.
Examples of activities performed in cyberspace include:
Modern society depends heavily on digital technology. Universities, banks, hospitals, government agencies, businesses and individuals store large amounts of information electronically. If these systems are not properly protected, criminals or other unauthorised persons may steal, alter, destroy or misuse the information.
Cybersecurity is important because it helps to:
Cybersecurity is practised when a person:
Network security protects communication networks and the data that moves through them. It uses technologies such as firewalls, intrusion detection systems, secure wireless settings and network monitoring.
Application security protects software programs from weaknesses that attackers may exploit. It begins during software design and continues through development, testing, deployment and maintenance.
Information security protects information in every form, including electronic files, printed documents and spoken information.
Cloud security protects information, applications and services stored or operated through cloud computing platforms.
Mobile security protects smartphones, tablets, mobile applications and information stored on mobile devices.
Internet of Things security protects devices that connect to the internet, such as smart cameras, sensors, smart televisions, health-monitoring devices and industrial equipment.
Operational technology security protects computer-controlled physical processes such as electricity generation, water treatment, manufacturing and transportation systems.
| Concept | Meaning |
|---|---|
| Cybersecurity | Protection of digital systems, networks, devices, applications and information from cyber threats. |
| Information Security | Protection of information in electronic, printed, verbal or other forms. |
| Computer Security | Protection of individual computers and their resources. |
| Network Security | Protection of networks, connected devices and transmitted information. |
| Data Privacy | Proper and lawful handling of personal information. |
| Physical Security | Protection of buildings, equipment and people from physical threats. |
Common cybersecurity challenges in Nigeria include:
Knowledge of cybersecurity must be used responsibly. Students must not attempt to access another person’s account, device, network or information without clear permission. Curiosity does not provide legal authorisation.
Cybersecurity protects computers, networks, applications, devices and information from unauthorised access, damage, disruption, theft and misuse. It is important to individuals, organisations and governments. Cybersecurity includes network security, application security, cloud security, mobile security and several other specialised areas.
At the end of this chapter, students should be able to:
A computer is an electronic device that accepts data, processes the data according to instructions, stores information and produces output.
A computer system consists mainly of:
Hardware refers to the physical parts of a computer system that can be seen or touched.
Examples include:
Software refers to the programs and instructions that tell a computer what to do.
System software controls the computer and provides a platform for other programs. The operating system is the most important example.
Examples of operating systems include:
Application software helps users perform specific tasks.
Examples include:
Data refers to raw facts, figures or symbols. Information is data that has been processed into a meaningful form.
For example, a list of examination scores is data. After calculating the average, ranking students and assigning grades, the results become meaningful information.
A computer network is a group of computers and other devices connected so that they can communicate and share resources.
A Local Area Network, commonly called a LAN, connects devices within a limited area such as a computer laboratory, office, home or university department.
A Wide Area Network, commonly called a WAN, connects devices across large geographical locations. The internet is the largest example of a wide area network.
A wireless network allows devices to communicate through radio signals instead of network cables. Wi-Fi is a common wireless networking technology.
| Device | Function |
|---|---|
| Router | Directs data between different networks. |
| Switch | Connects devices within a local network. |
| Modem | Connects a network to an internet service. |
| Wireless Access Point | Allows wireless devices to connect to a network. |
| Firewall | Controls network traffic according to security rules. |
| Server | Provides services or resources to other computers. |
A client is a device or program that requests a service. A server is a computer or program that provides the service.
When a student opens a university portal, the student’s browser acts as the client. The university web server receives the request and sends the requested page or information.
The internet is a global network of interconnected computer networks. The World Wide Web is a collection of websites and web pages accessed through the internet.
The internet and the web are related, but they are not exactly the same. The internet is the communication infrastructure, while the web is one of the services that operates through it.
An Internet Protocol address, known as an IP address, is a numerical identifier assigned to a device on a network. It helps network devices locate one another and exchange information.
A domain name is a human-readable name used to identify an internet resource. It is easier for people to remember a domain name than a numerical IP address.
The Domain Name System translates domain names into IP addresses. It performs a function similar to a contact list that connects a person’s name with a telephone number.
A web browser is an application used to access websites. Users should keep browsers updated because outdated browsers may contain security weaknesses.
A Uniform Resource Locator, known as a URL, is the address of a resource on the web.
A URL may contain:
HTTP is a protocol used to transfer web content. HTTPS is the protected form of HTTP. It uses encryption to protect information exchanged between a browser and a website.
The presence of HTTPS does not automatically prove that a website is honest. A fraudulent website can also use HTTPS. Users must still check the domain name and the purpose of the website.
Electronic mail is used to send messages and files through digital networks. Email is useful, but it is also commonly abused for phishing, fraud and malware distribution.
Cloud computing allows users to access computing resources through a network instead of owning and operating every resource locally.
Cloud services may provide:
The Internet of Things refers to physical devices containing sensors, software and network connections that allow them to collect and exchange information.
Examples include:
Cybersecurity protects an environment made up of hardware, software, data, users, networks, internet services, cloud platforms and connected devices. Understanding these basic technologies helps students understand where cyber threats occur and how protection can be applied.
At the end of this chapter, students should be able to:
The three most widely recognised objectives of information security are confidentiality, integrity and availability. Together, they are called the CIA triad.
Confidentiality means ensuring that information is accessible only to authorised persons, systems or processes.
Examples of confidentiality controls include:
For example, only authorised lecturers and examination officers should have access to students’ examination scores before the results are officially released.
Integrity means protecting information from unauthorised or accidental alteration, deletion or destruction. Information has integrity when it is accurate, complete and trustworthy.
Examples of integrity controls include:
If an unauthorised person changes a student’s score from 45 to 85, the integrity of the result has been violated.
Availability means ensuring that systems, services and information are accessible to authorised users when needed.
Examples of availability controls include:
If a university registration portal becomes unavailable throughout the registration period, availability has been affected.
Security decisions should consider confidentiality, integrity and availability together. Excessive security may make a system difficult to use, while insufficient security may expose it to attack.
For example, permanently disconnecting a university database from every network may improve confidentiality but make the database unavailable to authorised users.
Identification is the process by which a user claims an identity. A username, registration number or email address may serve as an identifier.
Authentication is the process of verifying that a person or system is truly who or what it claims to be.
Authentication may use:
Authorisation determines what an authenticated user is permitted to do.
A student may be authorised to view personal results but not to change them. A lecturer may be authorised to upload scores for assigned courses but not for every course in the university.
Accountability means that actions can be traced to the person or system that performed them. User accounts, logs and audit records support accountability.
Non-repudiation provides evidence that a person performed an action, making it difficult for the person to deny the action later. Digital signatures and reliable audit records can support non-repudiation.
Privacy is the right and ability of individuals to control how information about them is collected, used, stored, shared and deleted.
Cybersecurity supports privacy by protecting personal data from unauthorised access. However, privacy also involves legal, ethical and organisational responsibilities.
The principle of least privilege states that a user, program or system should receive only the minimum access required to perform an assigned duty.
For example, a student assistant helping to arrange books in a library should not automatically receive permission to change students’ academic records.
The need-to-know principle means that a person should access sensitive information only when that information is necessary for an authorised task.
Separation of duties divides important activities among two or more persons. This reduces fraud, error and misuse.
For example, one officer may prepare a payment, while another officer reviews and approves it.
Defence in depth means using several layers of security instead of depending on only one control.
A university system may use:
If one control fails, another control may still prevent or reduce the attack.
Security by design means considering security from the beginning of a system or application project rather than adding it only after problems occur.
Default deny means access should be refused unless it has been specifically permitted. This approach is safer than allowing every action and attempting to block only known dangers.
The CIA triad consists of confidentiality, integrity and availability. Other important cybersecurity principles include identification, authentication, authorisation, accountability, non-repudiation, privacy, least privilege, separation of duties, defence in depth and security by design.
At the end of this chapter, students should be able to:
An asset is anything that has value to an individual or organisation and therefore requires protection.
Examples of assets include:
Asset classification groups information according to its sensitivity and importance.
A simple classification system may include:
A threat is anything capable of causing harm to an asset.
Threats may be:
Examples include:
A vulnerability is a weakness that may be exploited by a threat.
Examples include:
An exploit is a method, action or piece of code used to take advantage of a vulnerability.
An attack is a deliberate attempt to compromise the confidentiality, integrity or availability of a system or its information.
An attack vector is the path or method used to reach and attack a target.
Examples include:
The attack surface is the total collection of points through which an attacker may attempt to enter, influence or extract information from a system.
A large number of unnecessary applications, accounts and network services increases the attack surface.
Risk is the possibility that a threat will exploit a vulnerability and cause harm to an asset.
Risk is commonly considered by examining:
A simple risk expression is:
Risk = Likelihood × Impact
Likelihood describes how probable it is that a threat will exploit a vulnerability.
Likelihood may be rated as:
Impact is the level of harm that may result from an incident.
Possible impacts include:
Suppose a university stores students’ records on a computer with no backup. The likelihood of hardware failure is rated 3, while the impact of losing all records is rated 5.
Risk Score = 3 × 5 = 15
If the organisation uses the following scale:
A score of 15 is a high risk and requires urgent treatment.
A security control is a measure used to prevent, detect, reduce or correct security problems.
For the risk of losing student records, possible controls include:
Residual risk is the risk that remains after security controls have been applied. It is usually impossible to remove every risk completely.
A risk register is a document used to record identified risks, affected assets, likelihood, impact, controls, responsible persons and treatment decisions.
| Asset | Threat | Vulnerability | Possible Impact | Control |
|---|---|---|---|---|
| Student records | Hardware failure | No backup | Permanent data loss | Daily backup and recovery testing |
| University portal | Account takeover | Weak passwords | Unauthorised access | Strong passwords and multifactor authentication |
| Computer laboratory | Theft | Weak physical security | Loss of equipment | Locks, guards and asset tracking |
Assets are valuable resources that require protection. Threats are potential causes of harm, while vulnerabilities are weaknesses that threats may exploit. Risk depends mainly on likelihood and impact. Security controls reduce risk, but some residual risk usually remains.
At the end of this chapter, students should be able to:
A threat actor is a person, group or organisation that intentionally or accidentally causes a cybersecurity incident.
Cybercriminals use computers and networks to commit crimes, usually for financial gain.
Their activities may include:
An insider is a person who has legitimate access to an organisation’s systems or information.
Insider threats may be:
Hacktivists use hacking activities to support political, social or ideological causes. Their actions may include website defacement, information leaks or service disruption.
Nation-state actors are groups supported or directed by governments. Their objectives may include intelligence gathering, political influence, military advantage or disruption of another country’s infrastructure.
Cyberterrorists use or threaten cyberattacks to create fear, cause serious disruption or advance extremist objectives.
Organised criminal groups conduct coordinated cybercrime for profit. They may divide responsibilities among malware developers, fraud operators, money handlers and sellers of stolen information.
A dishonest competitor may attempt to steal business secrets, customer information, research findings or strategic plans.
A script kiddie is an inexperienced person who uses tools or instructions developed by others without fully understanding how they work.
Limited technical knowledge does not make the activity harmless or legal.
Security researchers study systems to identify weaknesses and improve security. Their work must be performed with proper authorisation and responsible disclosure.
An ethical hacker is a security professional who is authorised to test systems for weaknesses. Ethical hacking is controlled by written permission, an agreed scope, professional standards and legal requirements.
| Description | Meaning |
|---|---|
| White Hat | An authorised security professional who tests systems to improve security. |
| Black Hat | A person who accesses or attacks systems for illegal or harmful purposes. |
| Grey Hat | A person who may test a system without proper permission, even when claiming a helpful purpose. |
The absence of malicious intention does not create permission. Testing a system without authorisation can still be unethical or unlawful.
Common motives include:
An internal threat originates from within an organisation, while an external threat originates outside it.
Insiders may be particularly dangerous because they may already understand the organisation’s systems and possess legitimate access.
A cyberattack may involve the following general stages:
This general description is provided for defensive understanding. Students must not apply it against unauthorised targets.
Threat actors include cybercriminals, insiders, hacktivists, organised criminal groups, nation-state actors, cyberterrorists and inexperienced attackers. Their motives may include money, revenge, ideology, espionage, recognition or disruption. Ethical security work requires clear authorisation.
At the end of this chapter, students should be able to:
Malware is software or code intentionally designed to damage systems, disrupt operations, steal information, spy on users or provide unauthorised access.
A computer virus is malicious code that attaches itself to a legitimate file or program. It normally spreads when the infected file is opened or executed.
A worm is malware that can copy and spread itself across networks without attaching itself to another file. Worms may spread quickly and consume network or system resources.
A Trojan horse is malware disguised as a useful or legitimate program. A user may install it believing it is a game, document, utility or application.
Ransomware is malware that blocks access to systems or encrypts files and demands payment for restoration.
Paying a ransom does not guarantee that files will be restored. Organisations should focus on prevention, secure backups and incident response.
Spyware secretly observes user activities or collects information without proper consent.
It may collect:
A keylogger records keys typed on a keyboard. It may capture usernames, passwords, messages and financial details.
Adware displays unwanted advertisements. Some adware also tracks user activity or changes browser settings.
A rootkit is designed to hide malicious activities and maintain privileged access to a system.
A backdoor is a hidden or undocumented method of bypassing normal authentication or security controls.
A bot is an infected device controlled remotely by an attacker. A botnet is a group of compromised devices controlled together.
Botnets may be used for:
A logic bomb is malicious code designed to activate when a particular condition is met, such as a date, time or system event.
Fileless malware operates mainly through legitimate system tools or computer memory rather than relying on a normal malicious file stored on the disk.
Malware may spread through:
Possible signs include:
These signs do not always prove that malware is present. Proper investigation is necessary.
Users and organisations should:
A user who suspects malware should:
Malware includes viruses, worms, Trojan horses, ransomware, spyware, keyloggers, rootkits, bots and other malicious programs. Malware may spread through email, unsafe downloads, infected devices and software weaknesses. Prevention depends on updates, secure configuration, backups, security software and user awareness.
At the end of this chapter, students should be able to:
Social engineering is the manipulation of people into revealing information, granting access or performing actions that weaken security.
Instead of attacking technology directly, a social engineer may exploit fear, trust, greed, curiosity, respect for authority or urgency.
Phishing is a fraudulent attempt to obtain information or persuade a person to perform an unsafe action through a deceptive message.
A phishing message may ask the victim to:
Spear phishing is a targeted phishing attack directed at a specific person, department or organisation. The attacker may use personal information to make the message appear convincing.
Whaling is phishing directed at senior officials, executives or other high-value individuals.
Smishing is phishing carried out through text messages or messaging applications.
Vishing is phishing carried out through telephone or voice communication.
Pretexting involves creating a false story or identity to persuade a victim to provide information or access.
An attacker may pretend to be a lecturer, bank official, technical support worker, delivery agent or government officer.
Baiting offers something attractive in order to persuade a victim to perform an unsafe action.
Examples include free software, free internet access, false scholarship forms or a flash drive left where someone is likely to pick it up.
Tailgating occurs when an unauthorised person follows an authorised person into a restricted area.
Shoulder surfing involves observing a person’s screen, keyboard or documents to obtain sensitive information.
Impersonation occurs when an attacker pretends to be another person in order to gain trust, information or access.
Scareware uses frightening messages to pressure a person into downloading software, paying money or contacting a fraudulent support service.
Business email compromise is a form of fraud in which an attacker impersonates or compromises a trusted business email account to request payment, confidential information or changes to payment details.
A student receives a message claiming that the student’s university account will be closed within thirty minutes unless the student enters a password through a provided link.
Warning signs include:
Organisations should:
Social engineering attacks human judgement rather than depending only on technical weaknesses. Common methods include phishing, vishing, smishing, pretexting, baiting, impersonation, tailgating and shoulder surfing. Verification, awareness and caution are essential defences.
At the end of this chapter, students should be able to:
Identity and Access Management refers to the policies, processes and technologies used to identify users, authenticate them and control their access to systems and information.
Access management commonly involves:
Examples include:
Examples include:
Examples include:
Multifactor authentication requires evidence from two or more different authentication-factor categories.
A password and a one-time code sent to a registered device may provide two factors because the password is something the user knows and the device is something the user has.
Two passwords are not true multifactor authentication because both belong to the same factor category.
A secure password should:
A passphrase is a long combination of words or characters used as a password. A well-constructed passphrase is often easier to remember and harder to guess than a short password.
A password manager is an application designed to generate, store and organise passwords securely. The user protects the password manager with a strong master password and, where possible, multifactor authentication.
Biometric authentication uses measurable physical or behavioural characteristics.
Advantages include:
Limitations include:
A one-time password is a code valid for only one login or transaction, or for a limited period. It should never be revealed to another person.
In discretionary access control, the owner of a resource may decide who receives access.
Mandatory access control uses centrally defined security classifications and rules. Individual users cannot freely change the rules.
Role-based access control assigns permissions according to job roles.
For example, students, lecturers, examination officers and system administrators may receive different permissions.
Attribute-based access control makes decisions using characteristics such as department, location, device, time, security status or type of information.
The lifecycle of a user account includes:
Privileged accounts have powerful permissions, such as the ability to install software, create users or change security settings. These accounts require stronger protection, monitoring and restricted use.
Account lockout and rate limiting reduce repeated login attempts. They help protect accounts from automated password guessing.
Identity and access management ensures that the right people receive the right access for the right purpose. It includes identification, authentication, authorisation and accounting. Strong passwords, multifactor authentication, secure account management and least privilege reduce unauthorised access.
At the end of this chapter, students should be able to:
Cryptography is the science and practice of protecting information by transforming it into a form that unauthorised persons cannot easily understand or alter.
Cryptography can support:
Classical ciphers are older techniques used to introduce cryptographic ideas. They are generally not secure enough for modern sensitive information.
The Caesar cipher replaces each letter with another letter located a fixed number of positions away in the alphabet.
Using a shift of three:
The word DATA becomes GDWD.
The Caesar cipher is useful for teaching, but it is not suitable for protecting modern information.
Symmetric encryption uses the same secret key, or closely related keys, for encryption and decryption.
Advantages include:
Its major challenge is securely sharing the secret key.
Asymmetric encryption uses a pair of mathematically related keys:
Information encrypted with the appropriate public key can be decrypted with the corresponding private key.
| Feature | Symmetric Encryption | Asymmetric Encryption |
|---|---|---|
| Number of keys | Normally one shared secret key | Public and private key pair |
| Speed | Generally faster | Generally slower |
| Key distribution | Secret key must be shared securely | Public key may be distributed openly |
| Common use | Protecting large amounts of data | Key exchange, authentication and digital signatures |
Hashing transforms data into a fixed-length output called a hash value or message digest.
A good cryptographic hash function should:
Encryption is designed to be reversed by an authorised person with the correct key. Hashing is normally designed as a one-way operation.
Secure systems should not normally store users’ passwords as readable text. They store protected password representations produced through appropriate password-hashing methods.
A salt is a unique random value added before hashing. Salting reduces the usefulness of precomputed password-guessing tables and prevents identical passwords from producing identical stored values.
A digital signature is a cryptographic mechanism used to support message integrity, authentication and non-repudiation.
A digital signature does not hide the message. Encryption may be used separately when confidentiality is required.
A digital certificate is an electronic document that links a public key to an identified person, organisation or system.
A certificate may contain:
A certificate authority is a trusted organisation that issues and manages digital certificates.
Public-Key Infrastructure is the combination of technologies, policies, certificates, authorities and procedures used to manage public-key cryptography.
Cryptography is used in:
Cryptography cannot solve every security problem. It may fail when:
Cryptography protects information through encryption, hashing, digital signatures and certificate systems. Symmetric encryption uses a shared secret key, while asymmetric encryption uses public and private keys. Hashing supports integrity and password protection, while digital signatures support authenticity and non-repudiation.
At the end of this chapter, students should be able to:
An endpoint is a device connected to a network, such as a desktop computer, laptop, smartphone, tablet or server.
Endpoint security is the protection of these devices from unauthorised access, malware and misuse.
System hardening is the process of reducing a system’s weaknesses and attack surface.
Hardening activities include:
A patch is a software update used to correct errors, improve performance or repair security vulnerabilities.
Patch management involves:
Antivirus software detects, blocks and removes known or suspicious malicious software. Modern endpoint protection may also monitor behaviour, network activity and unusual changes.
Security software must be updated and properly configured. No antivirus product provides complete protection.
A firewall monitors and controls network traffic according to security rules.
Firewalls may be:
An Intrusion Detection System monitors activities and alerts responsible personnel when suspicious behaviour is detected.
An Intrusion Prevention System can detect suspicious activity and automatically block or limit it according to configured rules.
Network segmentation divides a large network into smaller sections. This can limit the movement of attackers and reduce the effect of an incident.
For example, a university may separate student Wi-Fi, staff systems, financial systems, laboratory devices and public services.
A Virtual Private Network creates a protected communication connection across an untrusted network.
A VPN protects information in transit, but it does not automatically make every website safe or remove malware from a device.
Wireless networks should be protected by:
Public Wi-Fi may expose users to fake access points, traffic interception, account theft or malicious devices.
When using public Wi-Fi:
A denial-of-service attack attempts to make a system or service unavailable by overwhelming or disrupting it.
A distributed denial-of-service attack uses many devices, often from a botnet, to attack a target at the same time.
Eavesdropping is the unauthorised interception of communication. Encryption helps protect information against interception.
Spoofing involves falsifying identity or communication information to appear as a trusted system, user or source.
A man-in-the-middle attack occurs when an attacker secretly positions themselves between communicating parties to observe or alter information.
A secure backup should be:
Digital systems also require physical protection. Controls may include:
Computer and network security includes system hardening, software updates, endpoint protection, firewalls, intrusion detection, segmentation, secure wireless networking, backups and physical controls. Several layers should be combined to provide defence in depth.
At the end of this chapter, students should be able to:
Application security is the protection of software throughout its design, development, testing, deployment, operation and maintenance.
Secure software development includes:
Input validation checks information supplied by users or other systems before it is processed.
Applications should not automatically trust information entered through forms, uploaded files, addresses or external systems.
Broken access control occurs when an application fails to properly restrict what users are allowed to access or perform.
For example, a student should not gain access to another student’s academic record by changing a number in a web address.
Weak authentication may result from simple passwords, insecure password recovery, unlimited login attempts or poor session management.
A session represents a user’s active interaction with an application after login.
Secure session management includes:
A database is an organised collection of information. Database security protects stored data from unauthorised access, alteration, disclosure and destruction.
Database controls include:
Data minimisation means collecting and keeping only the information necessary for a legitimate purpose.
An organisation should not collect sensitive personal information simply because storage is available.
Cloud computing provides computing resources through a network on demand.
Infrastructure as a Service provides virtual computing resources such as servers, storage and networking.
Platform as a Service provides an environment in which developers can build and deploy applications.
Software as a Service provides complete applications accessed through a browser or application interface.
Cloud security is a shared responsibility between the cloud provider and the customer. The exact responsibilities depend on the service model.
The provider may secure the physical infrastructure, while the customer remains responsible for user accounts, passwords, permissions, information classification and secure application configuration.
Mobile users should:
Mobile applications may request access to the camera, microphone, contacts, messages, location or storage. Users should grant only permissions that are reasonably required.
Connected devices should be protected by:
Application security begins during design and continues throughout the software lifecycle. Important concerns include input validation, access control, authentication, sessions, database protection and secure configuration. Cloud security is shared between providers and customers. Mobile and connected devices also require updates, strong authentication and careful permission management.
At the end of this chapter, students should be able to:
Cybersecurity risk management is the organised process of identifying, assessing, treating, monitoring and communicating risks that may affect information and digital systems.
A basic risk management process includes:
Risk avoidance means stopping or not beginning the activity that creates the risk.
Risk mitigation means applying controls to reduce the likelihood or impact of the risk.
Risk transfer shifts part of the financial or operational responsibility to another party, such as through insurance or a service agreement.
Transfer does not always remove legal or reputational responsibility.
Risk acceptance means knowingly deciding to tolerate a risk because it is within approved limits or because treatment costs more than the expected harm.
Administrative controls include:
Technical controls include:
Physical controls include:
| Control Type | Purpose | Example |
|---|---|---|
| Preventive | Attempts to stop an incident before it occurs. | Firewall or access control |
| Detective | Identifies an incident or suspicious activity. | Audit log or intrusion detection |
| Corrective | Corrects the effect of an incident. | Removing malware |
| Recovery | Restores normal operations. | Restoring from backup |
| Deterrent | Discourages unacceptable behaviour. | Warning notice or visible camera |
| Compensating | Provides an alternative when the preferred control cannot be used. | Additional monitoring |
A security policy is a high-level statement of management’s expectations and rules for protecting an organisation’s assets.
Examples include:
A standard is a mandatory requirement that supports a policy.
A password policy may state that strong passwords must be used, while a password standard specifies the minimum approved requirements.
A procedure provides step-by-step instructions for performing a task.
For example, a password-reset procedure may describe how identity must be verified before a password is changed.
A guideline provides recommended practices. It normally allows more flexibility than a policy, standard or procedure.
A modern cybersecurity framework may organise cybersecurity activities into six broad functions:
Security awareness helps users recognise threats and understand their responsibilities.
Training should cover:
Cybersecurity risk changes over time. New systems, new users, new threats and new vulnerabilities may appear. Organisations should continuously monitor important systems and regularly review risks and controls.
A university identifies the risk of unauthorised access to student records because staff members use shared accounts.
Possible treatment measures include:
Cybersecurity risk management identifies, assesses, treats and monitors risks. Treatment options include avoidance, mitigation, transfer and acceptance. Controls may be administrative, technical or physical, and may perform preventive, detective, corrective or recovery functions. Policies, standards, procedures and guidelines help organisations apply security consistently.
At the end of this chapter, students should be able to:
A security event is an observable occurrence in a system or network. An event may be normal, suspicious or harmful.
Examples include a successful login, failed login, file download, system restart or firewall alert.
A security incident is an event or group of events that threatens or violates security policies, business operations or the confidentiality, integrity or availability of information.
Examples include:
A personal data breach is a security failure that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.
Incident response is the organised process of preparing for, detecting, analysing, containing, removing and recovering from cybersecurity incidents.
Preparation includes:
During identification, the organisation determines whether an incident has occurred.
Analysis may examine:
Containment limits the spread and effect of an incident.
Containment actions may include:
Containment decisions should consider both security and operational consequences.
Eradication removes the cause of the incident.
Activities may include:
Recovery restores systems and services to normal operation.
Recovery includes:
After the incident, the organisation should review:
Users should report incidents promptly through approved channels. Delay may allow the incident to spread or destroy valuable evidence.
An incident report may contain:
An incident response team may include:
Business continuity is the ability of an organisation to continue essential activities during and after disruption.
Disaster recovery focuses on restoring information technology systems, applications and information after a major disruption.
A backup is useful only when it can be successfully restored. Organisations must test backups and ensure they are protected from the same incident affecting the main system.
Digital forensics is the identification, collection, preservation, examination and presentation of digital evidence.
Students should not alter a suspected device carelessly because doing so may change or destroy evidence.
Chain of custody is the documented record of who collected, handled, transferred, examined and stored evidence.
A lecturer’s laptop containing examination scores is stolen.
Possible response actions include:
Incident response includes preparation, identification, analysis, containment, eradication, recovery and lessons learned. Timely reporting, documentation, backups and trained personnel reduce the impact of incidents. Business continuity keeps essential operations running, while disaster recovery restores technology.
At the end of this chapter, students should be able to:
Ethics refers to principles of right and wrong that guide behaviour. Cyber ethics applies ethical principles to the use of computers, networks, information and digital services.
A cybersecurity student should:
Authorisation is clear permission to perform an activity. Cybersecurity testing should be supported by written approval that defines:
A publicly accessible website is not automatically available for security testing.
Responsible disclosure is the process of privately reporting a discovered vulnerability to the system owner and allowing a reasonable opportunity for correction before wider publication.
A student who accidentally discovers a weakness should avoid exploiting it further, preserve relevant details and report it through an approved channel.
Intellectual property protects creations such as software, books, designs, music, research and inventions.
Unethical or unlawful activities may include:
Privacy concerns an individual’s control over personal life and personal information.
Data privacy focuses on the lawful, fair and responsible collection, use, storage, sharing and deletion of personal data.
Personal data is information relating to an identified or identifiable individual.
Examples include:
Some personal information requires stronger protection because misuse may cause serious harm or discrimination.
Examples may include:
A data controller determines the purposes and methods of processing personal data.
A data processor processes personal data on behalf of a data controller.
Personal data should generally be:
Depending on the applicable law and circumstances, individuals may have rights concerning:
The Nigeria Data Protection Act 2023 provides a national legal framework for protecting personal information and regulating the processing of personal data. It also establishes the Nigeria Data Protection Commission.
The Act addresses matters including:
Nigeria’s Cybercrimes legislation provides a legal framework for preventing, investigating and prosecuting various offences involving computers, electronic communications, networks and critical information systems.
The Cybercrimes (Prohibition, Prevention, etc.) Act 2015 was amended in 2024. Students and institutions should consult the current official text when detailed legal interpretation is required.
Cyber-related offences may involve:
Cyberbullying is the use of digital communication to harass, threaten, humiliate or repeatedly harm another person.
Identity theft occurs when a person unlawfully obtains or uses another person’s identifying information, usually for fraud or impersonation.
Online fraud involves deception through digital systems for financial or other unlawful gain.
Examples include:
An action may be legal but still unethical, or unethical conduct may later become the subject of legal action. Cybersecurity professionals should satisfy both legal requirements and professional ethical standards.
A student discovers that changing a number in a university portal address displays another student’s personal information.
The student should:
Cyber ethics guides responsible behaviour in digital environments. Cybersecurity activities require authorisation, respect for privacy and responsible disclosure. The Nigeria Data Protection Act 2023 regulates personal-data processing, while Nigeria’s Cybercrimes legislation addresses several computer-related offences.
At the end of this chapter, students should be able to:
Cybersecurity is a multidisciplinary profession involving computing, networking, law, management, risk, human behaviour, communication and investigation.
A Security Operations Centre analyst monitors systems, investigates alerts, identifies suspicious activity and supports incident response.
A cybersecurity analyst assesses threats, reviews security controls, monitors systems and recommends improvements.
A security engineer designs, implements and maintains security technologies and secure system architecture.
A penetration tester performs authorised security testing to identify weaknesses before malicious attackers exploit them.
Penetration testing requires written permission, an agreed scope and careful reporting.
An incident responder investigates and manages cybersecurity incidents, limits damage and supports recovery.
A digital forensics analyst collects, preserves and examines digital evidence.
A security auditor examines whether security controls, policies and practices meet established requirements.
A governance, risk and compliance professional helps an organisation manage security responsibilities, assess risks and comply with laws, standards and policies.
A security architect develops the overall structure and long-term design of an organisation’s security systems.
A cloud security specialist protects cloud applications, information, identities and infrastructure.
An application security specialist helps software developers design, test and maintain secure applications.
A data protection officer supports an organisation’s compliance with data-protection obligations and promotes responsible handling of personal information.
A cybersecurity researcher studies threats, vulnerabilities, defence methods, human behaviour and emerging technologies.
A student may:
Artificial intelligence may assist with threat detection, fraud analysis, malware classification and security automation.
Attackers may also use artificial intelligence to create convincing fraudulent messages, automate attacks or generate misleading content. Human oversight remains important.
The growth of cloud services creates demand for professionals who understand cloud identity, configuration, data protection and shared responsibility.
The increasing number of connected devices creates security challenges because many devices have limited processing power, weak default settings or long update cycles.
Operational technology controls physical processes. A security incident in such an environment may affect equipment, safety, production or public services.
Blockchain systems use distributed records and cryptographic techniques. They may provide useful capabilities, but applications built on them can still contain programming errors, stolen credentials, fraud or governance weaknesses.
Future large-scale quantum computers may affect some public-key cryptographic methods. Researchers are developing cryptographic methods intended to remain secure against quantum attacks.
Deepfakes are artificial or manipulated audio, images or video that may convincingly imitate real people or events. They may be used for fraud, impersonation and misinformation.
Zero trust is a security approach that avoids automatically trusting a user or device merely because it is inside an organisation’s network. Access decisions consider identity, device condition, context and least privilege.
Cybersecurity changes rapidly. Professionals must continually update their knowledge, practise responsibly and study new technologies, threats, standards and legal requirements.
Cybersecurity offers careers in monitoring, engineering, incident response, digital forensics, auditing, risk management, privacy, research and secure software development. Success requires technical knowledge, ethical conduct, communication and continuous learning. Emerging areas include artificial intelligence, cloud computing, connected devices, operational technology, blockchain, quantum-resistant cryptography and deepfake detection.
Cybersecurity protects computers, networks, applications, information and people from unauthorised access, attack, damage and disruption. Effective cybersecurity combines technology, people, policies, procedures, physical protection and responsible management.
The major security objectives are confidentiality, integrity and availability. Organisations must identify their assets, threats, vulnerabilities and risks before selecting appropriate security controls.
Common cyber threats include malware, phishing, account takeover, insider misuse, denial-of-service attacks and exploitation of poorly configured systems. Users can reduce their exposure through strong authentication, software updates, backups, careful internet use and prompt reporting.
Cybersecurity professionals must obey legal and ethical requirements. No system should be tested without proper authorisation. Nigerian students should understand the Nigeria Data Protection Act 2023 and the Cybercrimes Act 2015 as amended in 2024.
All practical activities must be performed on authorised systems, instructor-provided simulations, virtual machines or isolated laboratory networks. Students must not scan, intercept, access, modify or test real systems without written permission.
END OF CYB 101: INTRODUCTION TO CYBERSECURITY