Skip to content
Getting Digital

Cybersecurity

Security fundamentals

Every security blueprint opens with the same small set of ideas, and experienced practitioners still reach for them when a problem turns confusing. Confidentiality, integrity and availability; threat, vulnerability and risk; the difference between a control that prevents and one that merely detects. We treat that vocabulary as a working tool rather than an exam chapter, because people who skip it spend years buying answers to questions they never stated.

Why this topic exists: Every blueprint opens here: the CIA triad, control types and the threat, vulnerability and risk vocabulary (SY0-701 General Security Concepts, 12 %; CISSP domain 1).

Security fundamentals is less a body of facts than a disciplined way of asking questions. Before anyone buys a product or writes a rule, somebody has to state what is being protected, from whom, and what a failure would cost. The terms below exist so that a network engineer, a developer and a finance director can hold that conversation without talking past each other.

  • Confidentiality, integrity, availability. The three properties a system can lose. A leaked customer database is a confidentiality failure, a tampered invoice an integrity failure, a website knocked offline an availability failure. Real incidents usually damage more than one, and most controls protect one far better than the others: encryption guards secrecy and does nothing for uptime.
  • Threat, vulnerability, risk. A threat is someone or something able to cause harm, a vulnerability is the weakness they would use, and risk is the likelihood and impact of the two meeting. Beginners use the words interchangeably; exams punish that, and so do budget meetings.
  • Control categories and functions. Controls are technical, managerial, operational or physical, and they prevent, detect, correct, deter or compensate. A camera deters and detects, a lock prevents, a restored backup corrects. Knowing the function tells you what is still missing.
  • Proving identity and action. Authentication settles who someone is, authorisation what they may do, accounting what they did. Non-repudiation, the property that a sender cannot later deny a message, rests on hashing and digital signatures.
  • Defence in depth and least privilege. No single control is trusted to hold alone, and nobody holds more access than the task needs. Almost every other topic in this silo eventually comes back to least privilege.

How the blueprints use this material

Security+ gives these ideas a domain of their own at the start of the exam, and they return inside every later domain as the reasoning behind the correct answer. The CISSP places them in its first and heaviest domain, security and risk management, but examines them from the other chair: not what a control is, but whether it is proportionate to the risk and who should approve it. Microsoft's SC-900 and the free certificates from IBM and Fortinet cover similar ground more lightly and are a sensible first check of whether the subject holds your interest.

The shortcut that costs beginners most

The usual mistake is treating fundamentals as the dull chapter to get through before the real material. People who do this can name twenty attack techniques and still cannot explain why one of them matters more to their organisation than another, which is the only question an employer actually pays for. It shows in exam results as well. Scenario questions in Security+ are rarely about recalling a term and usually about choosing the control whose function fits the problem described, so a candidate who has memorised the vocabulary without using it picks the plausible option rather than the right one. Stay on this material until you can explain a recent breach from the news in its terms: which property failed, which weakness was used, which type of control would have changed the outcome.

Where to go next

Most readers continue to threats and attacks, which puts faces on this vocabulary, or to identity and access management, where least privilege becomes daily work. Security+ certifies this level, and the glossary entry on risk assessment connects it to the management side of the field.

Next to this topic

Concepts to know

Glossary entries with the reason each one matters here.

  • Authentication

    Proving who you are is the first control every blueprint names.

  • Encryption

    Confidentiality in the CIA triad is delivered by encryption.

  • Hashing

    Integrity checks and password storage rest on one-way hashes.

  • Least Privilege

    The design principle Security+ tests before any product.

  • Security Risk Assessment

    Threat, vulnerability and risk are the vocabulary of the field's first domain.

Certifications that test it

Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.

Frequently asked

What is the CIA triad in plain terms?
Three questions about any piece of information: can only the right people see it, can you trust that nobody altered it, and can people reach it when they need to. Every control you will meet protects at least one of those, and a useful habit is naming which one before judging whether the control is worth its cost.
Is SC-900 or Security+ the better first exam?
They do different jobs. SC-900 is short and maps the concepts onto one vendor's products, which suits people already working in that ecosystem. Security+ is vendor-neutral, much broader and far more often named in job adverts, which makes it the clearer signal for anyone aiming at a security role.
How long should I spend on fundamentals before specialising?
Until you can use the terms to reason, not just define them: a few weeks of steady study for most people with an IT background, longer without one. The test is whether you can take any incident report and say which property failed and which control type would have helped.

Courses in the directory

114 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.

Browse the directory shelf

Last reviewed 26 September 2026 · Getting Digital