The CSX Fundamentals Course is designed to provide an overview of this material, as well as to offer insight into the importance of cybersecurity and the integral role of cybersecurity professionals. This course will also cover four key areas of cybersecurity:
A pre-assessment provided to attendees will assist the instructor in determining the baseline
knowledge of participants, as well as any necessary demographic information. Results from the
pre-assessment should be used to help focus lecture and activities to be most meaningful to all
participants. The pre-assessment should include questions regarding:
1.1. Introduction to cybersecurity
1.2. Difference between information security and cybersecurity
1.3. Cybersecurity objectives
1.4. Cybersecurity roles
1.5. Cybersecurity domains
2.1. Risk
2.2. Common attack types and vectors
2.3. Policies and procedures
2.4. Cybersecurity controls
3.1. Overview of security architecture
3.2. The OSI model
3.3. Defense in depth
3.4. Information flow control
3.5. Isolation and segmentation
3.6. Logging, monitoring and detection
3.7. Encryption fundamentals, techniques and applications
4.1. Process controls—Risk assessment
4.2. Process controls—Vulnerability management
4.3. Process controls—Penetration testing
4.4. Network security
4.5. Operating system security
4.6. Application security
4.7. Data security
5.1. Event vs. incident
5.2. Security incidentresponse
5.3. Investigations, legal holds, and preservation
5.4. Forensics
5.5. Disaster recovery and business continuity
6.1. Current threat landscape
6.2. Advanced persistent threats(APTs)
6.3. Mobile technology—Vulnerabilities, threats, and risk
6.4. Consumerization of IT and mobile devices
6.5. Cloud and digital collaboration