Please enable JavaScript to use CodeHS

Standards Mapping

for Arkansas Cybersecurity

Clear selection Print / Download

76

Standards in this Framework

59

Standards Mapped

77%

Mapped to Course

Standard Lessons
1.1.1
Maintain clear documentation and audit trails of all security activities, ensuring compliance requirements are met.
  1. AP Cybersecurity
  2. 2.6 Risky Business: Turning Risk Into a Plan (Cyber Foundations)
  3. 5.5 Data in the Wrong Hands: Classification, Regulation & Policy (Protecting Applications and Data)
  4. 5.21 Reading the Attack: Log Analysis for Application Attacks (Detecting Attacks on Data and Applications)
1.1.2
Operate strictly within defined scope and authorization boundaries, including proper handling of sensitive data and following escalation procedures when needed.
1.1.3
Communicate security findings and recommendations effectively to both technical and non-technical stakeholders, adapting language and detail level appropriately.
  1. Advanced Cybersecurity
  2. 9.3 Risk Response
  3. AP Cybersecurity
  4. 2.9 Capstone: Coffee Shop Consultant (Cyber Foundations)
  5. 5.15 Capstone: The VitalLink Security Consult (Asymmetric Cryptography)
  6. 5.21 Reading the Attack: Log Analysis for Application Attacks (Detecting Attacks on Data and Applications)
1.1.4
Apply project management methodologies to security initiatives, including resource planning, timeline management, and measuring success metrics against defined objectives.
1.1.5
Create and deliver a security awareness training session for a specific audience.
  1. Advanced Cybersecurity
  2. 10.2 Level 2: User Training
  3. AP Cybersecurity
  4. 2.13 Small Habits, Big Security Impact (Protecting Physical Spaces)
  5. 5.12 Two Keys Are Better Than One (Asymmetric Cryptography)
1.1.6
Analyze use cases and security considerations regarding Artificial Intelligence and Machine Learning.
  1. AP Cybersecurity
  2. 1.6 AI Has Entered the Chat (AI-Based Cybersecurity Attacks)
  3. 1.7 Using AI as Your Defense (AI-Based Cybersecurity Attacks)
  4. 1.8 When AI and Humans Team Up (Leveraging AI in Cyber Defense)
  5. 1.9 The AI Security Guard (Leveraging AI in Cyber Defense)
  6. 3.15 AI-Powered Threat Detection (Detecting Network Attacks)
1.2.1
Map cybersecurity careers to required skills and qualifications (e.g., using the NICE Cybersecurity Workforce Framework).
  1. Advanced Cybersecurity
  2. 16.1 After Advanced Cybersecurity
  3. AP Cybersecurity
  4. 1.1 Welcome to Cybersecurity!
1.2.2
Analyze cybersecurity job market trends and requirements (e.g., studying local industry needs).
1.2.3
Compare and contrast common entry-level cybersecurity roles and their responsibilities (e.g., Junior SOC Analyst, Security Administrator, Information Security Analyst).
2.1.1
Identify and categorize common cyber threats using industry frameworks (e.g., MITRE ATT and CK for Beginners).
  1. AP Cybersecurity
  2. 2.1 The Art of Deception (Cyber Foundations)
  3. 2.2 Anatomy of a Cyberattack (Cyber Foundations)
2.1.2
Analyze different types of attack vectors (e.g., phishing, malware, social engineering) and their potential impacts.
  1. Fundamentals of Cybersecurity
  2. 1.7 Common Cyber Attacks and Prevention
  3. Advanced Cybersecurity
  4. 3.1 Network Attacks
  5. 3.2 Malware Types and Prevention
  6. 3.3 Common Network Attacks
  7. AP Cybersecurity
  8. 1.3 The Tricks Behind Every Scam (Understanding Social Engineering)
  9. 2.1 The Art of Deception (Cyber Foundations)
  10. 3.2 Traffic in the Wrong Hands (Network Vulnerabilities and Attacks)
  11. 4.2 The Adversary's Toolkit (Device Vulnerabilities and Attacks)
  12. 5.2 When Input Becomes an Attack (Application and Data Vulnerabilities and Attacks)
2.1.3
Create basic defense strategies for common cyber threats (e.g., implementing strong passwords, enabling multi-factor authentication, regularly patching software).
  1. Fundamentals of Cybersecurity
  2. 1.5 Personal Data Security
  3. AP Cybersecurity
  4. 1.4 Lock It Down With Better Passwords (Suspicious Website Logins)
  5. 2.8 Building Strong Cyber Defenses (Cyber Foundations)
  6. 4.7 Can You Prove It's You? (Authentication)
  7. 4.9 Writing the Rules Devices Follow (Protecting Devices)
  8. 4.10 Defend the Device (Protecting Devices)
2.2.1
Diagram the steps (e.g., passive/active reconnaissance, privilege escalation) of common cyber attacks (e.g., password cracking, SQL injection).
  1. Fundamentals of Cybersecurity
  2. 8.3 Security in Coding
  3. 8.6 Checking for Vulnerabilities
  4. Advanced Cybersecurity
  5. 9.1 Identifying Risks
  6. 9.2 Assessing Risks
  7. AP Cybersecurity
  8. 2.2 Anatomy of a Cyberattack (Cyber Foundations)
  9. 2.3 Breaking In and Staying In (Cyber Foundations)
  10. 4.5 Cracking the Hash (Authentication)
  11. 5.2 When Input Becomes an Attack (Application and Data Vulnerabilities and Attacks)
2.2.2
Identify attack methods used in recent cybersecurity incidents.
  1. Advanced Cybersecurity
  2. 4.2 Cyber Case Investigation
  3. AP Cybersecurity
  4. 1.1 Welcome to Cybersecurity!
  5. 2.1 The Art of Deception (Cyber Foundations)
  6. 2.8 Building Strong Cyber Defenses (Cyber Foundations)
2.2.3
Identify warning signs of potential cyber attacks (e.g., unusual network activity, phishing emails, unexpected system slowdowns).
  1. AP Cybersecurity
  2. 1.3 The Tricks Behind Every Scam (Understanding Social Engineering)
  3. 3.18 The Story in the Logs (Detecting Network Attacks)
  4. 4.13 Inside the Security Logs (Detecting Attacks on Devices)
2.3.1
Define scope of security test and obtain written consent (e.g., determine which systems will be tested, what types of tests will be performed, and secure formal authorization from the client).
2.3.2
Use vulnerability scanning tools to detect and identify known vulnerabilities (e.g., Nessus, OpenVAS, QualysGuard).
  1. Fundamentals of Cybersecurity
  2. 8.6 Checking for Vulnerabilities
  3. Advanced Cybersecurity
  4. 9.1 Identifying Risks
  5. 9.2 Assessing Risks
  6. AP Cybersecurity
  7. 4.3 How Adversaries Get In (Device Vulnerabilities and Attacks)
2.3.3
Document vulnerability findings through a process (e.g., creating vulnerability reports, researching CVE databases, writing security advisories).
  1. Fundamentals of Cybersecurity
  2. 8.7 Risky Business
  3. Advanced Cybersecurity
  4. 9.1 Identifying Risks
  5. 9.2 Assessing Risks
  6. AP Cybersecurity
  7. 2.9 Capstone: Coffee Shop Consultant (Cyber Foundations)
  8. 4.4 What's Worth Protecting? (Device Vulnerabilities and Attacks)
2.4.1
Compare and contrast different types of threat intelligence (strategic, tactical, operational, technical) and their uses.
2.4.2
Analyze threat intelligence feeds and reports from various sources (e.g., ISACs, vendor reports, government advisories).
2.4.3
Practice using threat intelligence platforms and tools to gather, analyze, and share intelligence (e.g., MISP, ThreatConnect, Recorded Future).
2.4.4
Apply threat intelligence to enhance detection and prevention capabilities (e.g., block known malicious IP addresses, create custom detection rules, prioritize patching efforts based on current threats).
  1. AP Cybersecurity
  2. 3.12 Writing the Rulebooks (Protecting Networks: Firewalls)
  3. 3.16 Choosing Between Detection Methods (Detecting Network Attacks)
3.1.1
Apply classic ciphers and cryptographic concepts (e.g., Caesar Cipher, Vigenère Cipher).
  1. Fundamentals of Cybersecurity
  2. 2.1 Cryptography: Then, Now, and Future
  3. 2.2 Symmetric Encryption
  4. AP Cybersecurity
  5. 5.9 Keys, Blocks, and Streams (Protecting Stored Data with Cryptography)
  6. 6.5 Unit 5: Securing Applications and Data
3.1.2
Demonstrate symmetric cryptography principles (e.g., AES (Advanced Encryption Standard), DES (Data Encryption Standard)).
  1. Fundamentals of Cybersecurity
  2. 2.2 Symmetric Encryption
  3. Advanced Cybersecurity
  4. 1.1 Advanced Cryptography
  5. AP Cybersecurity
  6. 5.9 Keys, Blocks, and Streams (Protecting Stored Data with Cryptography)
  7. 5.10 The Advanced Encryption Standard (Protecting Stored Data with Cryptography)
  8. 5.11 Tools for AES (Protecting Stored Data with Cryptography)
3.1.3
Implement asymmetric cryptography methods (e.g., RSA (Rivest-Shamir-Adleman), Diffie-Hellman key exchange).
  1. Fundamentals of Cybersecurity
  2. 2.3 Asymmetric Encryption
  3. Advanced Cybersecurity
  4. 1.4 Asymmetric Encryption
  5. AP Cybersecurity
  6. 5.12 Two Keys Are Better Than One (Asymmetric Cryptography)
  7. 5.13 More Keys Than Stars (Asymmetric Cryptography)
  8. 5.14 Tools for RSA (Asymmetric Cryptography)
3.1.4
Analyze and identify hash functions (e.g., SHA-256, MD5 (though MD5 is now considered insecure)).
  1. Advanced Cybersecurity
  2. 1.2 Hash Functions
  3. 1.3 Hash Function Development
  4. AP Cybersecurity
  5. 4.5 Cracking the Hash (Authentication)
  6. 5.20 Verifying File Integrity with Hashes (Detecting Attacks on Data and Applications)
3.1.5
Identify digital signatures in practical scenarios (e.g., Secure email communication, software authentication).
  1. Fundamentals of Cybersecurity
  2. 2.4 Authentication Methods
  3. Advanced Cybersecurity
  4. 1.5 Digital Certificates
3.1.6
Configure PKI and implement key management (e.g., Setting up a certificate authority (CA), key generation and distribution).
3.2.1
Apply steganography to hide data (e.g., using a hex editor).
  1. Advanced Cybersecurity
  2. 2.1 Project: Steganography
3.2.2
Identify weak passwords through the use of hash analysis (e.g., detecting commonly used password patterns, identifying passwords that don't meet complexity requirements, finding instances of password reuse across accounts).
  1. AP Cybersecurity
  2. 4.6 Passwords Under Attack (Authentication)
3.2.3
Apply fundamental data protection methods (e.g., encryption, access controls, secure backup procedures).
  1. AP Cybersecurity
  2. 5.6 Who Gets In? Access Control Models (Protecting Applications and Data)
  3. 5.7 Locking Down Files: Linux Permissions (Protecting Applications and Data)
  4. 5.9 Keys, Blocks, and Streams (Protecting Stored Data with Cryptography)
3.2.4
Write programs to encode/decode and encrypt/decrypt data (e.g., implementing base64 encoding for safe data transmission, creating a file encryption utility using standard libraries, developing a secure message encoding system).
4.1.1
Identify vulnerabilities presented by open ports and protocols running on a system (e.g., ssh on port 22, FTP on 20/21).
  1. Fundamentals of Cybersecurity
  2. 8.6 Checking for Vulnerabilities
  3. Advanced Cybersecurity
  4. 6.2 Protocols and Standards
  5. AP Cybersecurity
  6. 3.10 The Rules of the Firewall (Protecting Networks: Firewalls)
  7. 4.3 How Adversaries Get In (Device Vulnerabilities and Attacks)
4.1.2
Use basic network security tools to identify common misconfigurations and vulnerabilities (e.g., nmap, Nessus).
  1. AP Cybersecurity
  2. 3.7 Locking Down the Airwaves (Protecting Networks: Managerial Controls and Wireless Security)
  3. 4.3 How Adversaries Get In (Device Vulnerabilities and Attacks)
4.1.3
Identify security measures as they relate to each layer of the TCP/IP Model (e.g., MAC filtering on layer 2).
4.2.1
Use network traffic monitoring tools to capture and analyze potentially malicious traffic (e.g.,using wireshark to identify packet anomalies).
  1. Advanced Cybersecurity
  2. 7.4 Networking Services
  3. AP Cybersecurity
  4. 3.18 The Story in the Logs (Detecting Network Attacks)
4.2.2
Identify different network endpoints and consider controls for each (e.g., virtual machines, servers, etc.).
  1. AP Cybersecurity
  2. 4.1 Everything is a Computer (Device Vulnerabilities and Attacks)
  3. 4.10 Defend the Device (Protecting Devices)
4.2.3
Configure network security controls (e.g., firewalls, network segmentation, IDSs, ACLs).
  1. Advanced Cybersecurity
  2. 7.3 Network Design
  3. 7.4 Networking Services
  4. AP Cybersecurity
  5. 3.8 Network Segmentation (Protecting Networks: Segmentation)
  6. 3.10 The Rules of the Firewall (Protecting Networks: Firewalls)
  7. 3.12 Writing the Rulebooks (Protecting Networks: Firewalls)
  8. 3.13 Capstone: Firewalls in Practice (Protecting Networks: Firewalls)
  9. 3.14 The Automated Detectors (Detecting Network Attacks)
5.1.1
Demonstrate knowledge of basic cybersecurity frameworks and their purpose (e.g., NIST Cybersecurity Framework for beginners).
  1. AP Cybersecurity
  2. 1.2 The Rules of the Game
5.1.2
Analyze how different industries handle cybersecurity requirements (e.g., healthcare, education, banking).
  1. AP Cybersecurity
  2. 2.6 Risky Business: Turning Risk Into a Plan (Cyber Foundations)
  3. 5.6 Who Gets In? Access Control Models (Protecting Applications and Data)
  4. 5.15 Capstone: The VitalLink Security Consult (Asymmetric Cryptography)
5.1.3
Create basic security guidelines and procedures for an organization (e.g., password requirements for employees, acceptable use of company devices).
  1. Advanced Cybersecurity
  2. 10.2 Level 2: User Training
  3. AP Cybersecurity
  4. 3.6 The Network's Rulebook (Protecting Networks: Managerial Controls and Wireless Security)
  5. 4.9 Writing the Rules Devices Follow (Protecting Devices)
5.2.1
Compare and contrast and apply professional codes of ethics in cybersecurity (e.g., (ISC)² Code of Ethics, ISACA Code of Professional Ethics).
5.2.2
Develop and apply ethical decision-making frameworks when confronting security dilemmas and conflicting responsibilities.
5.2.3
Identify and resolve potential conflicts of interest in cybersecurity roles (e.g., disclosing relationships with vendors, avoiding personal gain from security recommendations, refusing gifts that could influence decision-making).
5.2.4
Balance security requirements with business objectives in case studies or simulations.
  1. AP Cybersecurity
  2. 1.4 Lock It Down With Better Passwords (Suspicious Website Logins)
  3. 2.7 The Risk Response Playbook (Cyber Foundations)
  4. 5.13 More Keys Than Stars (Asymmetric Cryptography)
  5. 5.19 Choosing the Right Controls (Detecting Attacks on Data and Applications)
5.3.1
Analyze key privacy regulations and their requirements (e.g., HIPAA, FERPA, GDPR).
  1. Fundamentals of Cybersecurity
  2. 1.5 Personal Data Security
  3. AP Cybersecurity
  4. 1.4 Lock It Down With Better Passwords (Suspicious Website Logins)
  5. 5.5 Data in the Wrong Hands: Classification, Regulation & Policy (Protecting Applications and Data)
5.3.2
Apply data classification and handling procedures to protect sensitive information (e.g., retention, destruction, or disposal of data).
  1. AP Cybersecurity
  2. 5.5 Data in the Wrong Hands: Classification, Regulation & Policy (Protecting Applications and Data)
  3. 5.8 Capstone: Defending a Real System (Protecting Applications and Data)
5.3.3
Design solutions that incorporate privacy-by-design principles.
  1. AP Cybersecurity
  2. 5.16 Secure by Design & Secure by Default (Protecting Applications)
5.3.4
Conduct privacy impact assessments for new systems and processes.
5.3.5
Monitor and report privacy breaches and incidents following regulatory requirements.
  1. AP Cybersecurity
  2. 5.5 Data in the Wrong Hands: Classification, Regulation & Policy (Protecting Applications and Data)
  3. 5.21 Reading the Attack: Log Analysis for Application Attacks (Detecting Attacks on Data and Applications)
5.4.1
Apply principles of least privilege and separation of duties (e.g., restricting database administrators from modifying application code, requiring two-person approval for critical system changes, limiting user access to only required resources).
  1. AP Cybersecurity
  2. 5.6 Who Gets In? Access Control Models (Protecting Applications and Data)
5.4.2
Implement role-based access control (RBAC) and attribute-based access control (ABAC).
  1. AP Cybersecurity
  2. 5.6 Who Gets In? Access Control Models (Protecting Applications and Data)
5.4.3
Review and verify user access rights periodically to ensure appropriate permissions are maintained (e.g., quarterly access reviews,understanding supervisor certification of employee access levels).
5.4.4
Monitor and audit access patterns for suspicious activity (e.g., detecting off-hours system access, identifying unusual data download volumes, spotting multiple login attempts from unfamiliar locations).
  1. AP Cybersecurity
  2. 4.13 Inside the Security Logs (Detecting Attacks on Devices)
  3. 4.15 Detecting Password Attacks in the Wild (Detecting Attacks on Devices)
5.4.5
Demonstrate understanding of how user lifecycle is managed from onboarding through termination.
6.1.1
Identify and categorize basic security risks in IT systems (e.g., unpatched software vulnerabilities, weak password policies, unsecured network ports).
  1. Advanced Cybersecurity
  2. 9.1 Identifying Risks
  3. AP Cybersecurity
  4. 2.5 Risk Fundamentals: What Could Go Wrong? (Cyber Foundations)
  5. 4.3 How Adversaries Get In (Device Vulnerabilities and Attacks)
  6. 4.4 What's Worth Protecting? (Device Vulnerabilities and Attacks)
  7. 4.10 Defend the Device (Protecting Devices)
6.1.2
Create simple threat models for common scenarios (e.g., school network, mobile app).
  1. AP Cybersecurity
  2. 2.6 Risky Business: Turning Risk Into a Plan (Cyber Foundations)
  3. 3.8 Network Segmentation (Protecting Networks: Segmentation)
6.1.3
Develop basic risk management plans with practical solutions (e.g., implementing a regular software update schedule, establishing a data backup strategy, creating an incident response playbook).
  1. Fundamentals of Cybersecurity
  2. 8.7 Risky Business
  3. Advanced Cybersecurity
  4. 9.3 Risk Response
  5. AP Cybersecurity
  6. 2.6 Risky Business: Turning Risk Into a Plan (Cyber Foundations)
  7. 2.7 The Risk Response Playbook (Cyber Foundations)
6.2.1
Use basic risk assessment tools and checklists (e.g., NIST SP 800-30, ISO 27005, FAIR).
  1. AP Cybersecurity
  2. 2.5 Risk Fundamentals: What Could Go Wrong? (Cyber Foundations)
  3. 2.6 Risky Business: Turning Risk Into a Plan (Cyber Foundations)
6.2.2
Practice monitoring and measuring security controls (e.g., reviewing audit logs, tracking vulnerability scan results, monitoring intrusion detection system alerts).
  1. AP Cybersecurity
  2. 3.14 The Automated Detectors (Detecting Network Attacks)
  3. 3.17 Evaluating Detection Methods (Detecting Network Attacks)
  4. 3.18 The Story in the Logs (Detecting Network Attacks)
  5. 4.13 Inside the Security Logs (Detecting Attacks on Devices)
6.2.3
Update security plans based on new threats and lessons learned.
  1. Advanced Cybersecurity
  2. 10.3 Level 3: Incident Response
  3. 10.5 Level 5: Change Management
  4. AP Cybersecurity
  5. 3.10 The Rules of the Firewall (Protecting Networks: Firewalls)
  6. 3.13 Capstone: Firewalls in Practice (Protecting Networks: Firewalls)
7.1.1
Use basic security monitoring tools (e.g., log analyzers, network monitors).
  1. AP Cybersecurity
  2. 3.14 The Automated Detectors (Detecting Network Attacks)
  3. 3.18 The Story in the Logs (Detecting Network Attacks)
  4. 4.13 Inside the Security Logs (Detecting Attacks on Devices)
7.1.2
Practice following incident detection procedures through scenarios (e.g., investigating an unexpected spike in failed login attempts, responding to customer reports of system slowdowns, analyzing patterns of unusual database queries).
  1. AP Cybersecurity
  2. 4.13 Inside the Security Logs (Detecting Attacks on Devices)
  3. 4.15 Detecting Password Attacks in the Wild (Detecting Attacks on Devices)
  4. 5.21 Reading the Attack: Log Analysis for Application Attacks (Detecting Attacks on Data and Applications)
7.1.3
Create and understand basic security alerts (e.g., detecting multiple failed authentication attempts within a short timeframe, identifying unauthorized access to sensitive files, monitoring for unusual outbound network traffic patterns).
  1. AP Cybersecurity
  2. 3.14 The Automated Detectors (Detecting Network Attacks)
  3. 3.16 Choosing Between Detection Methods (Detecting Network Attacks)
  4. 5.20 Verifying File Integrity with Hashes (Detecting Attacks on Data and Applications)
7.2.1
Develop and implement incident response plans through scenario-based exercises.
  1. Advanced Cybersecurity
  2. 10.3 Level 3: Incident Response
7.2.2
Document security incidents and generate post-incident reports.
  1. Advanced Cybersecurity
  2. 10.3 Level 3: Incident Response
  3. AP Cybersecurity
  4. 4.15 Detecting Password Attacks in the Wild (Detecting Attacks on Devices)
  5. 5.21 Reading the Attack: Log Analysis for Application Attacks (Detecting Attacks on Data and Applications)
7.2.3
Develop and test basic incident recovery procedures.
  1. Advanced Cybersecurity
  2. 10.3 Level 3: Incident Response
8.1.1
Identify and document system components, boundaries, and interactions (e.g., creating network diagrams, documenting data flow, identifying critical assets).
  1. AP Cybersecurity
  2. 2.5 Risk Fundamentals: What Could Go Wrong? (Cyber Foundations)
  3. 3.8 Network Segmentation (Protecting Networks: Segmentation)
  4. 5.5 Data in the Wrong Hands: Classification, Regulation & Policy (Protecting Applications and Data)
8.1.2
Apply CIA (Confidentiality, Integrity, Availability) principles to assess system impacts.
  1. AP Cybersecurity
  2. 1.2 The Rules of the Game
  3. 2.5 Risk Fundamentals: What Could Go Wrong? (Cyber Foundations)
  4. 5.4 How Do You Measure Risk? (Application and Data Vulnerabilities and Attacks)
8.1.3
Evaluate system vulnerabilities and dependencies.
  1. Advanced Cybersecurity
  2. 9.1 Identifying Risks
  3. 9.2 Assessing Risks
  4. AP Cybersecurity
  5. 3.4 How Adversaries Get Into Your Network (Network Vulnerabilities and Attacks)
  6. 4.3 How Adversaries Get In (Device Vulnerabilities and Attacks)
  7. 5.3 When the Boundaries Break (Application and Data Vulnerabilities and Attacks)
8.2.1
Integrate security requirements in system planning and design phases (e.g., conducting threat modeling, defining security architecture, selecting secure hardware and software).
  1. AP Cybersecurity
  2. 3.8 Network Segmentation (Protecting Networks: Segmentation)
  3. 3.13 Capstone: Firewalls in Practice (Protecting Networks: Firewalls)
  4. 5.16 Secure by Design & Secure by Default (Protecting Applications)
8.2.2
Apply appropriate security controls based on system requirements.
  1. AP Cybersecurity
  2. 2.8 Building Strong Cyber Defenses (Cyber Foundations)
  3. 5.8 Capstone: Defending a Real System (Protecting Applications and Data)
  4. 5.19 Choosing the Right Controls (Detecting Attacks on Data and Applications)
8.2.3
Perform security testing and validation throughout development stages.
  1. AP Cybersecurity
  2. 4.11 Host Firewalls (Protecting Devices)
  3. 5.3 When the Boundaries Break (Application and Data Vulnerabilities and Attacks)
8.3.1
Evaluate and report on system security controls effectiveness.
  1. AP Cybersecurity
  2. 3.17 Evaluating Detection Methods (Detecting Network Attacks)
  3. 4.14 Smart Detection Choices (Detecting Attacks on Devices)
  4. 5.19 Choosing the Right Controls (Detecting Attacks on Data and Applications)
8.3.2
Document system security architecture and controls (e.g., diagrams of network segmentation, lists of access control rules, descriptions of encryption methods).
  1. AP Cybersecurity
  2. 3.8 Network Segmentation (Protecting Networks: Segmentation)
  3. 3.12 Writing the Rulebooks (Protecting Networks: Firewalls)
  4. 3.13 Capstone: Firewalls in Practice (Protecting Networks: Firewalls)
  5. 5.15 Capstone: The VitalLink Security Consult (Asymmetric Cryptography)
8.3.3
Update security measures based on system changes and emerging threats.
  1. Advanced Cybersecurity
  2. 10.5 Level 5: Change Management
  3. AP Cybersecurity
  4. 1.7 Using AI as Your Defense (AI-Based Cybersecurity Attacks)
  5. 3.10 The Rules of the Firewall (Protecting Networks: Firewalls)
  6. 4.10 Defend the Device (Protecting Devices)