Live webinars on information security
Karnesav
Karnesav
Information Security Beginner

Information Security Fundamentals: Core Concepts Course

6 weeks, 3 hours per week
Information Security Fundamentals: Core Concepts Course

Most people encounter security through incidents — a phishing email, a data breach in the news, a locked account. This course works the other way: it builds a clear picture of how security works before problems appear.

What this course covers

You will work through the core pillars of information security: confidentiality, integrity, and availability. Each concept is grounded in real scenarios — not abstract definitions. You will look at how attackers think, what they target, and why certain controls exist.

Threats and attack surfaces

The course examines common threat categories — social engineering, malware, insider risk, and network-level attacks. Each is covered with enough technical detail to be useful without requiring a background in networking or programming.

Controls and risk management

Security controls are not all technical. This section covers administrative, physical, and technical controls, and explains how organizations decide which risks to accept, mitigate, or transfer. You will practice basic risk assessment using simple frameworks.

Security is not a product you install. It is a set of decisions made continuously under uncertainty.

By the end of the course, you will be able to read a security policy, participate in a risk discussion, and identify gaps in basic security setups. This is a foundation — it takes consistent practice to build further.

Course materials include readings, scenario exercises, and short knowledge checks after each module.
Program
  1. Security Concepts and the CIA Triad

    Definitions, real-world examples, and why these three properties underpin every security decision.

  2. Threat Landscape Overview

    Categories of threats, attacker motivations, and how incidents typically unfold.

  3. Authentication and Access Control

    Passwords, multi-factor authentication, least privilege, and identity management basics.

  4. Network Security Basics

    Firewalls, VPNs, network segmentation, and what traffic analysis reveals.

  5. Malware and Social Engineering

    How malware spreads, phishing mechanics, and practical detection habits.

  6. Security Controls and Frameworks

    Technical, administrative, and physical controls. Introduction to NIST and ISO 27001 frameworks.

  7. Risk Assessment in Practice

    Identifying assets, estimating likelihood and impact, and documenting a basic risk register.

  8. Incident Response Fundamentals

    What to do when something goes wrong — detection, containment, and reporting basics.