Cybersecurity
Security fundamentals
Every security blueprint opens with the same small set of ideas, and experienced practitioners still reach for them when a problem turns confusing. Confidentiality, integrity and availability; threat, vulnerability and risk; the difference between a control that prevents and one that merely detects. We treat that vocabulary as a working tool rather than an exam chapter, because people who skip it spend years buying answers to questions they never stated.
Why this topic exists: Every blueprint opens here: the CIA triad, control types and the threat, vulnerability and risk vocabulary (SY0-701 General Security Concepts, 12 %; CISSP domain 1).
Security fundamentals is less a body of facts than a disciplined way of asking questions. Before anyone buys a product or writes a rule, somebody has to state what is being protected, from whom, and what a failure would cost. The terms below exist so that a network engineer, a developer and a finance director can hold that conversation without talking past each other.
- Confidentiality, integrity, availability. The three properties a system can lose. A leaked customer database is a confidentiality failure, a tampered invoice an integrity failure, a website knocked offline an availability failure. Real incidents usually damage more than one, and most controls protect one far better than the others: encryption guards secrecy and does nothing for uptime.
- Threat, vulnerability, risk. A threat is someone or something able to cause harm, a vulnerability is the weakness they would use, and risk is the likelihood and impact of the two meeting. Beginners use the words interchangeably; exams punish that, and so do budget meetings.
- Control categories and functions. Controls are technical, managerial, operational or physical, and they prevent, detect, correct, deter or compensate. A camera deters and detects, a lock prevents, a restored backup corrects. Knowing the function tells you what is still missing.
- Proving identity and action. Authentication settles who someone is, authorisation what they may do, accounting what they did. Non-repudiation, the property that a sender cannot later deny a message, rests on hashing and digital signatures.
- Defence in depth and least privilege. No single control is trusted to hold alone, and nobody holds more access than the task needs. Almost every other topic in this silo eventually comes back to least privilege.
How the blueprints use this material
Security+ gives these ideas a domain of their own at the start of the exam, and they return inside every later domain as the reasoning behind the correct answer. The CISSP places them in its first and heaviest domain, security and risk management, but examines them from the other chair: not what a control is, but whether it is proportionate to the risk and who should approve it. Microsoft's SC-900 and the free certificates from IBM and Fortinet cover similar ground more lightly and are a sensible first check of whether the subject holds your interest.
The shortcut that costs beginners most
The usual mistake is treating fundamentals as the dull chapter to get through before the real material. People who do this can name twenty attack techniques and still cannot explain why one of them matters more to their organisation than another, which is the only question an employer actually pays for. It shows in exam results as well. Scenario questions in Security+ are rarely about recalling a term and usually about choosing the control whose function fits the problem described, so a candidate who has memorised the vocabulary without using it picks the plausible option rather than the right one. Stay on this material until you can explain a recent breach from the news in its terms: which property failed, which weakness was used, which type of control would have changed the outcome.
Where to go next
Most readers continue to threats and attacks, which puts faces on this vocabulary, or to identity and access management, where least privilege becomes daily work. Security+ certifies this level, and the glossary entry on risk assessment connects it to the management side of the field.
Next to this topic
- Network securityFirewalls, segmentation, IDS/IPS, VPNs and zero trust are where most defensive work starts (CISSP Communication and Network Security, 13 %; Network+ and CCNA security domains).
- Identity and access managementWho may do what is its own discipline with its own exam (SC-300) and a full CISSP domain (13 %): authentication, MFA, SSO, directories and least privilege.
- CryptographyEncryption, hashing, keys and PKI underlie every other topic; the exams test them as applied choices, not maths (CISSP Security Architecture and Engineering; SY0-701 domain 1).
- Threats and attacksThe second-largest Security+ domain (Threats, Vulnerabilities and Mitigations, 22 %; only Security Operations weighs more): malware, phishing, social engineering, ransomware and the attack techniques defenders must recognise.
- Security operationsMonitoring, detection and the SOC are the largest Security+ domain (28 %) and the whole of SC-200 and CySA+: SIEM, logging, alert triage, threat hunting.
- Penetration testing and ethical hackingAuthorised attack as a profession: scoping, reconnaissance, exploitation, reporting (PTES; PenTest+ and CEH). Also the most-searched security topic on the course side.
- Governance, risk and compliancePolicies, risk assessment, frameworks (NIST CSF, ISO 27001) and audit are the management half of the field: CISSP domain 1 (16 %), CISM, CISA, Security+ Program Management (20 %).
- Application securityA large share of breaches begins in software: secure design, secure build, security testing and the OWASP Top 10 (OWASP SAMM; CISSP Software Development Security, 10 %).
- Cloud securityShared responsibility, cloud identity and posture management are tested in every cloud exam (SAA-C03 Design Secure Architectures, 30 %) and in SC-900; the cloud silo owns the platforms, this topic owns the defence.
- Security awareness for everyoneMost incidents start with a person, not a port: what every employee and freelancer must know about phishing, passwords, MFA, backups and updates (NICE Oversight and Governance; the management side of every blueprint).
Concepts to know
Glossary entries with the reason each one matters here.
- Authentication
Proving who you are is the first control every blueprint names.
- Encryption
Confidentiality in the CIA triad is delivered by encryption.
- Hashing
Integrity checks and password storage rest on one-way hashes.
- Least Privilege
The design principle Security+ tests before any product.
- Security Risk Assessment
Threat, vulnerability and risk are the vocabulary of the field's first domain.
Certifications that test it
Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.
- CompTIA · SY0-701CompTIA Security+The entry exam whose first domain is this topic.
- Microsoft · SC-900Microsoft Certified: Security, Compliance, and Identity FundamentalsMicrosoft's vocabulary-level security exam.
- Cisco · Online exam, not proctored · freeIntroduction to CybersecurityA free first course with a badge.
- IBM · Online exam, not proctored · freeCybersecurity FundamentalsA free attacker-first introduction.
Frequently asked
- What is the CIA triad in plain terms?
- Three questions about any piece of information: can only the right people see it, can you trust that nobody altered it, and can people reach it when they need to. Every control you will meet protects at least one of those, and a useful habit is naming which one before judging whether the control is worth its cost.
- Is SC-900 or Security+ the better first exam?
- They do different jobs. SC-900 is short and maps the concepts onto one vendor's products, which suits people already working in that ecosystem. Security+ is vendor-neutral, much broader and far more often named in job adverts, which makes it the clearer signal for anyone aiming at a security role.
- How long should I spend on fundamentals before specialising?
- Until you can use the terms to reason, not just define them: a few weeks of steady study for most people with an IT background, longer without one. The test is whether you can take any incident report and say which property failed and which control type would have helped.
Courses in the directory
114 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.
Introduction to Cyber Security
The Open University
Introduction to Cybersecurity for Teachers
Raspberry Pi Foundation
Last reviewed 26 September 2026 · Getting Digital
